OID for Kerberos Principal Name

Kevin Coffman kwc at umich.edu
Thu Jul 29 11:47:23 EDT 2010


Does this help?

http://mailman.mit.edu/pipermail/krbdev/2006-November/005180.html

K.C.

On Thu, Jul 29, 2010 at 11:22 AM, Bram Cymet <bcymet at cbnco.com> wrote:
> Hi,
>
> I am attempting to get pkinit working. I am using my own custom CA to
> generate the certs and I am having a little trouble generating a correct
> Subject Alternative Name (SAN) in my certs.
>
> I have been able to generate a cert with a Microsoft Universal Principal
> Name OID: 1.3.6.1.4.1.311.20.2.3
>
> However when I use this cert the kdc says 'unrecognized othername oid in
> SAN'
>
> Can anyone tell me what the correct OID that I should be using is so
> that I don't get a 'client name mismatch' error?
>
> This is for MIT kerberos.
>
> Thanks,
>
> Bram Cymet
>
>
>
> ________________________________________________
> Kerberos mailing list           Kerberos at mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
>




More information about the Kerberos mailing list