<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CA manager approval required for certificate re-enrollment</title><link>http://blogs.technet.com/b/pki/archive/2011/03/08/ca-manager-approval-required-for-certificate-re-enrollment.aspx</link><description>Hi there, this is Larry, Developer from US, and Fabian, PFE from Germany, writing about an uncommon scenario that might raise questions sometimes. 
 When enrolling certificates to clients or users, you might want to have control regarding the initial</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: CA manager approval required for certificate re-enrollment</title><link>http://blogs.technet.com/b/pki/archive/2011/03/08/ca-manager-approval-required-for-certificate-re-enrollment.aspx#3483139</link><pubDate>Sat, 25 Feb 2012 08:34:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3483139</guid><dc:creator>Fabian Müller [MSFT]</dc:creator><description>&lt;p&gt;Hi Christian,&lt;/p&gt;
&lt;p&gt;Larry provided the following answers: :-)&lt;/p&gt;
&lt;p&gt;(#1) The topic we documented holds true for renewals, regardless of whether they are auto enroll initiated or manually initiated.&lt;/p&gt;
&lt;p&gt;(#2) You are correct that you cannot have a UPN within the subject, only within the SAN. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;The difference in behavior between offline and online templates is that for offline, the SAN is not evaluated, only the subject. &amp;nbsp;In this case, regardless of whether it is a user or machine cert, the subject information must match. &amp;nbsp;This means that the previously mentioned requirement that SAN contain either a UPN or email address does not apply. Of course, with Windows 7 the new client code provides the ability to auto-renew offline templates, so this makes this scenario a lot easier than it has been in the past. &amp;nbsp;The client automatically populates the renewal cert request with the subject info from the cert that is being renewed.&lt;/p&gt;
&lt;p&gt;HTH&lt;/p&gt;
&lt;p&gt;Fabian&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3483139" width="1" height="1"&gt;</description></item><item><title>re: CA manager approval required for certificate re-enrollment</title><link>http://blogs.technet.com/b/pki/archive/2011/03/08/ca-manager-approval-required-for-certificate-re-enrollment.aspx#3482802</link><pubDate>Thu, 23 Feb 2012 16:49:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3482802</guid><dc:creator>Christian Skoglund</dc:creator><description>&lt;p&gt;Question #1&lt;/p&gt;
&lt;p&gt;For the online template it works if you do manuell reenroll in the GUI &amp;quot;Renew Certificate with new key&amp;quot;.&lt;/p&gt;
&lt;p&gt;If you instead use Autoenrollment, the reenrolled certificate request will be pending in the CA.&lt;/p&gt;
&lt;p&gt;Any idea? Is this supposed to work?&lt;/p&gt;
&lt;p&gt;Question #2&lt;/p&gt;
&lt;p&gt;You write about that name matching in offline templates only evaluate the subject name. You say that namematching only use email or upn. What about computer objects? What I now you can not have a UPN in the subject name, only in the SAN.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;
&lt;p&gt;Christian&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3482802" width="1" height="1"&gt;</description></item></channel></rss>