Skip to content
arrow_back
search
ISM-1948 policy ASD Information Security Manual (ISM)

Approval for Certificate Template SANs in AD Services

Approval is needed before using certificate templates that let you specify extra names.

record_voice_over

Plain language

If your business uses certificates to secure communications, it's crucial to have someone approve the templates that allow adding extra identifying information. Without this approval, you might mistakenly trust incorrect details, which could lead to data leaks or fraud.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

CA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.
policy ASD Information Security Manual (ISM) ISM-1948
priority_high

Why it matters

Unapproved SANs in AD CS certificate templates can enable issuance for unauthorised hostnames, supporting spoofing and man-in-the-middle attacks.

settings

Operational notes

Ensure templates that permit requester-supplied SANs require CA Certificate Manager approval; periodically revalidate approvals and remove or restrict unnecessary SAN-enabled templates.

Mapping detail

Mapping

Direction

Controls