SSCEP: Subject of our request does not match that of the returned Certificate!

Assume the following scenario:

sscep: Subject of our request does not match that of the returned Certificate!

The Network Device Enrollment Service (NDES) provides a way for devices that do not have an identifier in Active Directory (for example, network devices such as routers, switches, printers, thin clients, or smartphones and tablets) to request certificates from a certification authority. For a more detailed description, see the article "Network Device Enrollment Service (NDES) Basics„.

SSCEP compares the subject of the submitted certificate request with the issued certificate.

sscep: decrypting inner PKCS#7
sscep: PKCS#7 payload size: 2005 bytes
write_local_cert(): found 1 cert(s)
sscep: found certificate with
subject: '/OU=IT/O=ADCS lab/CN=testsceprequest'
issuer: /C=DE/ST=Bavaria/L=Munich/O=ADCS Lab/OU=IT/CN=ADCS Lab Issuing CA 1
request_subject: '/O=ADCS Lab/OU=IT/CN=testsceprequest'
Subject of the returned certificate: /OU=IT/O=ADCS Lab/CN=testsceprequest
Subject of the request: /O=ADCS Lab/OU=IT/CN=testsceprequest
X509_NAME_cmp() workaround: strcmp request subject (/O=ADCS Lab/OU=IT/CN=testsceprequest) to cert subject (/OU=IT/O=ADCS Lab/CN=testsceprequest)
sscep: Subject of our request does not match that of the returned certificate!
sscep: certificate written as local.crt

If this message appears, the certificate was successfully issued by the certification authority, but the requested subject was not recognized by the certification authority based on the defined rules changedso that the comparison by SSCEP fails.

Possible solutions may include:

Related links:

2 thoughts on “SSCEP: Subject of our request does not match that of the returned Certificate!”

Comments are closed.

en_USEnglish