This article describes how to map an objectSid certificate for Microsoft Knowledge Base 5014754 (KB5014754) and how Active Directory users' objectSid attributes can be loaded to Smart ID Identity Manager, converted and used to issue new certificates with a strong mapping.
Do the following:
In Identity Manager, add the objectSid attribute to the LDAP data pool. In the field list, select the data type Hexadecimal Text.
Map the LDAP data pool field containing the objectSid to a normal text field in the user data pool.
Create an additional field for the converted SID.
Use a script to convert the hexadecimal representation to the original string value.
|
Add the objectSID attribute to the certificate template. For more information, see Set up certificate template in Identity Manager.
Verify the SID in the 1.3.6.1.4.1.311.25.2 attribute of the issued certificate.
For more information, see Nexus awareness advisory on Microsoft’s update KB5014754.