EnrollmentFlagsV3
class EnrollmentFlagsV3
Template configurations for v3 template schema.
Types
Properties
Link copied to clipboard
Allow renewal using the same key.
Link copied to clipboard
Include symmetric algorithms allowed by the subject.
Link copied to clipboard
This flag instructs the CA to not include the security extension szOID_NTDS_CA_SECURITY_EXT (OID:1.3.6.1.4.1.311.25.2), as specified in [MS-WCCE] sections 2.2.2.7.7.4 and 3.2.2.6.2.1.4.5.9, in the issued certificate. This addresses a Windows Kerberos elevation-of-privilege vulnerability.
Link copied to clipboard
Delete expired or revoked certificates instead of archiving them.
Link copied to clipboard
Require user interaction when the subject is enrolled and the private key associated with the certificate is used.