[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Implementation of DN vs. SubjAltName Field
We are attempting to accommodate a migration from a PKI that will initially
start with a dedicated PKI directory structure to a corporate directory
structure with different DIT's. A view is to utilize the SubjAltNAme field
with the email as the unique identifier . This would then be the key field
to populate the corporate DS when that time comes. My understanding is that
if you use a DN in the Subject Field, a change in DIT would require
reissuance of the certificate.
Any pointers to additonal information to better understand how applications
utilize the Subject Field for obtaining information about the certificate
would be appreciated.
Murray Yutzy
Lockheed Martin
407/306-1917
Orlando,FL