Skip to content

Instantly share code, notes, and snippets.

@CJHarms
Last active May 16, 2023 16:32
Show Gist options
  • Select an option

  • Save CJHarms/279d8f177c2d199cf9036cb9683bac49 to your computer and use it in GitHub Desktop.

Select an option

Save CJHarms/279d8f177c2d199cf9036cb9683bac49 to your computer and use it in GitHub Desktop.
Microsoft AD CS Intermediate CAPolicy.inf Example
[Version]
Signature="$Windows NT$"
;[RequestAttributes]
;CertificateTemplate=ExampleSubCA
[PolicyStatementExtension]
Policies=InternalPolicy,AllIssuancePolicy
[AllIssuancePolicy]
OID=2.5.29.32.0
;Notice="Internal PKI Legal Policy Statement"
URL=http://pki.example.com/pki/cps
[InternalPolicy]
OID=1.2.3.4.1455.67.89.5
Notice="Internal PKI Legal Policy Statement"
URL=http://pki.example.com/pki/cps
[Certsrv_Server]
RenewalKeyLength=4096
RenewalValidityPeriod=Years
RenewalValidityPeriodUnits=20
LoadDefaultTemplates=0
AlternateSignatureAlgorithm=0
;[EnhancedKeyUsageExtension]
;OID=1.3.6.1.5.5.7.3.4 ; Secure Mail
;OID=1.3.6.1.4.1.311.20.2.2 ; Smart Card Logon
;OID=1.3.6.1.5.5.7.3.2 ; Client Authentication
;OID=1.3.6.1.5.5.7.3.1 ; Server Authentication
;Critical=No
[BasicConstraintsExtension]
Pathlength = 1
Critical = true
;[NameConstraintsExtension]
;Include = NameConstraintsPermitted
;Exclude = NameConstraintsExcluded
;Critical = true
;[NameConstraintsPermitted]
;DirectoryName = "DC=corp,DC=gnetworks,DC=org"
;DirectoryName = "DC=gnetworks,DC=org"
;DNS = .corp.gnetworks.org
;DNS = .gnetworks.org
;email = @corp.gnetworks.org
;email = @gnetworks.org
;UPN = .corp.gnetworks.org
;UPN = @corp.gnetworks.org
;UPN = .gnetworks.org
;UPN = @gnetworks.org
;[NameConstraintsExcluded]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment