Replies: 1 comment
-
Option 1. You can configure Windows to not require the extension, which is still secure if your AD is configured securely. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
i try to get logon on Windows 11 with a yubikey an a samba ad
At first I used this tutorial to setup the certificates
everythink works as expected.
Then I ve setup ejbca the same way and it had generated certificated which worked the same way
Now Microsoft hast changend the certificates with the update 04 22 (KB5014754)
take a look here https://www.gradenegger.eu/?p=18373#more-18373
now ejbca ee has added the support for the szOID_NTDS_CA_SECURITY_EXT exention.
is there a way to add this extension to ejbca ce? And how is it to add?
thanks a lot
Beta Was this translation helpful? Give feedback.
All reactions