So I'm sure this is as simple an answer as it appears, but I need to make sure.
I created a cert for a new DC, installed it, all looks good. Tested
LDAP and LDAPS, and that all passed. That's when I noticed that I had
misspelled one of the SANs on the certificate. LOL I have the FQDN as
a SAN, and just the short hostname. But I mispelled the short hostname
...
I should just be able to create a new CSR, with the right SAN, issue a
new cert (from our own CA, I mean). Then I can just add it to the DC
the usual way, "certreq -accpt "corrected named cert"?
The new cert will just replace the old one, and I can then go and
revoke it in my CA.
--
Mike. Leone, <mailto:
tur...@mike-leone.com>
PGP Fingerprint: 0AA8 DC47 CB63 AE3F C739 6BF9 9AB4 1EF6 5AA5 BCDF
Photo Gallery: <
http://www.flickr.com/photos/mikeleonephotos>