Security – Code Signing Enroll User For Different Domain
This is how to enroll into a cert from the users computer.
How Users Enroll for Certificates with Custom ("Different") Domain Name
Users with Enroll permission can now request a certificate:
Option A – Using MMC (easiest for testing)
- Run certmgr.msc (Current User).
- Right-click Personal → All Tasks → Request New Certificate.
- Select your enrollment policy (Active Directory Enrollment Policy).
- Choose your new template.
- When prompted, click Details → Properties.
- On Subject tab: Enter custom values (e.g., Common name = "OtherDomain Code Signing Authority").
- On Subject tab: Enter custom values (e.g., Organtization = "SFL Services LLC").
- On Subject tab: Enter custom values (e.g., Locality = "Loveland").
- On Subject tab: Enter custom values (e.g., State = "Ohio").
- On Subject tab: Enter custom values (e.g., Country = "US").
- On Extensions tab: Add SAN if needed (e.g., email=signing@otherdomain.com).
- Enroll.
Using certreq.exe (scriptable / automated) Create an .inf file:
[Version] Signature="$Windows NT$" [NewRequest] Subject = "CN=Code Signing, O=SFL Services LLC, L=Loveland, S=Ohio, C=US" ; You can make Subject empty if you prefer only SAN / no CN, but most code signing tools expect a CN KeySpec = 1 KeyLength = 4096 ; 3072 or 4096 is strongly recommended in 2025+ Exportable = TRUE ; Usually yes for code signing MachineKeySet = FALSE ; User context (most common for code signing) SMIME = FALSE PrivateKeyArchive = FALSE UserProtected = FALSE UseExistingKeySet = FALSE ProviderName = "Microsoft Enhanced RSA and AES Cryptographic Provider" ProviderType = 24 RequestType = PKCS10 KeyUsage = 0x80 ; digitalSignature = required for code signing [EnhancedKeyUsageExtension] OID=1.3.6.1.5.5.7.3.3 ; Code Signing EKU ; Optional: if you really want to add DNS SANs (rare for pure code signing) [Extensions] 2.5.29.17 = "{text}" _continue_ = "dns=www.sflservicesllc.com&" _continue_ = "email=sales@sflservicesllc.com" Then:
certreq -new codesign-request.inf codesign.csr certutil -dump codesign.csr certreq -submit -attrib "CertificateTemplate:YourTemplateName" codesign.csr codesign.cer certreq -accept codesign.cer certutil -store my