IX509Extension XCN encoding?

Viewed 437

I understand from reading MSDN that the X509 v3 extensions must be handcrafted. This involves the CRL, AIA, name and policy constraints, policy mapping, private key usage period, and subject directory attributes.

I tried to make a CRL distribution point but the result is garbage:

    $crlExt = New-Object -ComObject X509Enrollment.CX509Extension
    $crlOid = New-Object -ComObject X509Enrollment.CObjectId
    $crlOid.InitializeFromValue('2.5.29.31')
    $crlValue = [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes('http://www.test.com'))
    $crlExt.Initialize($crlOid, 0x1, $crlValue)
    $crlExt.Critical = $false

Is there any reference on how to encode the values for each of the following? I have searched all over but no luck.

  • AuthorityInformationAccess
  • CrlDistributionPoints
  • FreshestCRL
  • NameConstraints
  • PolicyConstraints
  • PolicyMappings
  • PrivateKeyUsagePeriod
  • SubjectDirectoryAttributes

Note that this is about the certenroll com interface in Windows. openssl is not applicable here.

1 Answers
Related