When using Active Directory Certificates, it is noticeable that there are certain extensions in the certificates of the certification authorities and the certificates they issue that are not defined in the relevant RFCs and are specific to AD CS.
Tag: Certificate Profile
Description of the EDITF_ADDOLDKEYUSAGE flag
When installing a subordinate certificate authority, you may encounter the following behavior:
- One requests a Key Usage extension that is marked as critical, for example, or does not include DigitalSignature.
- However, the certificate issued by the parent certificate authority includes DigitalSignature, and the Key Usage extension is marked as non-critical.
- The parent certification authority is a standalone certification authority, i.e. without Active Directory integration.