Skip to main content
Question

ADCS - CN equals

  • April 24, 2023
  • 3 replies
  • 66 views

Forum|alt.badge.img+12

Our machine certificates are formatted by hostname.domain.com

Within the certificate payload, should I use CN=$COMPUTERNAME.domain.com or CN=$HOSTNAME.domain.com? 

I was hoping I could do it by DNS name only  - but the Certificate payload requires a subject.

 

 

3 replies

sdagley
Forum|alt.badge.img+25
  • Jamf Heroes
  • April 24, 2023

@k3vmo We use user certificates instead of device certs, so I can't answer this from direct experience, but I don't see $HOSTNAME as a valid variable for a Jamf Pro Configuration Profile (in https://learn.jamf.com/bundle/jamf-pro-documentation-current/page/Computer_Configuration_Profiles.html#ID-00022bba). Since $HOSTNAME should be equivalent to $COMPUTERNAME.comain.com I would recommend going with CN=$COMPUTERNAME.domain.com


BL-ay
Forum|alt.badge.img+2
  • New Contributor
  • April 25, 2023

We use computer certificates but with the serial number as UPN. For other extensions I used $COMPUTERNAME as Hostname.


mm2270
Forum|alt.badge.img+24
  • Legendary Contributor
  • April 25, 2023

What @sdagley said. Use CN=$COMPUTERNAME.domain.com That should work.