Replies: 1 comment
-
Option 1. You can configure Windows to not require the extension, which is still secure if your AD is configured securely. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
i try to get logon on Windows 11 with a yubikey an a samba ad
At first I used this tutorial to setup the certificates
everythink works as expected.
Then I ve setup ejbca the same way and it had generated certificated which worked the same way
Now Microsoft hast changend the certificates with the update 04 22 (KB5014754)
take a look here https://www.gradenegger.eu/?p=18373#more-18373
now ejbca ee has added the support for the szOID_NTDS_CA_SECURITY_EXT exention.
is there a way to add this extension to ejbca ce? And how is it to add?
thanks a lot
Beta Was this translation helpful? Give feedback.
All reactions