Re: Certificate Installation Question

From: Sam Salhi [MSFT] (samers_at_online.microsoft.com)
Date: 11/03/04

  • Next message: Sam Salhi [MSFT]: "Re: packetsize IAS can receive"
    Date: Wed, 3 Nov 2004 09:46:43 -0800
    
    

    look for a tool called Certificate manager tool:
    http://msdn.microsoft.com/library/default.asp?url=/library/en-us/cptools/html/cpgrfcertificatemanagertoolcertmgrexe.asp
    use it with this command line:

    certmgr -add RootCert.cer -r localMachine -s root

    -- 
          =============================================
      This posting is provided "AS IS" with no warranties, and confers no 
    rights.
          =============================================
    "CG" <cg@cg.com> wrote in message 
    news:eG$qciawEHA.3668@tk2msftngp13.phx.gbl...
    >I can do that - no problem.
    >
    > However, for my users, is there a way I can automate this so that it goes 
    > to the correct store? Is there a command line utility that I can import 
    > this cert to? And if there is, what are the commands to make that happen?
    >
    > We are going to try to package a config so our users can run it and not 
    > have to interact with it.
    >
    > Thanks Sam.
    >
    > "Sam Salhi [MSFT]" <samers@online.microsoft.com> wrote in message 
    > news:eGZgeBTwEHA.3084@TK2MSFTNGP10.phx.gbl...
    >> When you import the certificate, just click "View physical store" and 
    >> expand trusted root certificate authority and select machine store
    >>
    >>
    >> -- 
    >>      =============================================
    >>  This posting is provided "AS IS" with no warranties, and confers no 
    >> rights.
    >>      =============================================
    >>
    >> "CG" <cg@cg.com> wrote in message 
    >> news:%23fSk9LRwEHA.3768@TK2MSFTNGP10.phx.gbl...
    >>>I am using the Certificate Services webpage for my users to sign up and
    >>> download their certs (we aren't running AD). The Client Authentication 
    >>> cert
    >>> gets installed in the Local Computer store right where it is supposed to 
    >>> be.
    >>> When they download the CA certification path it is installed ONLY in the
    >>> Current User store. This is the case whether they click the "Install 
    >>> this CA
    >>> certification path" link or if they click the "Download CA certification
    >>> path" and import with the wizard. If they have the Wizard automatically
    >>> decide to put the cert where it is supposed to go it always installs it 
    >>> in
    >>> the Current User store. When I try to authenticate with the Client
    >>> Authentication cert in the local store and the CA in the Current User I 
    >>> get
    >>> an error 786. I export the CA from the Current User store and import it 
    >>> into
    >>> the Local Computer into Trusted CA and everything works fine.
    >>>
    >>> My question is- is there anyway to have the Trusted CA to into the Local
    >>> Computer store? Is this configurable on the CA server somewhere?
    >>>
    >>> With the CMAK - is it possible to build a config that includes the certs 
    >>> and
    >>> will put them into the Local Computer store?
    >>>
    >>>
    >>>
    >>
    >>
    >
    > 
    

  • Next message: Sam Salhi [MSFT]: "Re: packetsize IAS can receive"

    Relevant Pages

    • Re: Issues with SSL on Win CE 5.0
      ... the HKCU certificate store. ... and tell the web server to use it. ... The old cert was in. ...
      (microsoft.public.windowsce.embedded)
    • Re: Active Directory Federation Services
      ... that is associated with their profile and the machine itself has a store. ... Just wanted to let you know that I got the cert problem fixed. ... the user certificate store. ... FSP was looking for certs in the local ...
      (microsoft.public.windows.server.active_directory)
    • Re: Accessing certificate store from ASP.NET web project
      ... the cert must be in the local computer/personal) store - it will then open ... Have a look at the source code to open the right cert store... ... One of the locations requires a x509 certificate in order ... different user context than my vb.net web project. ...
      (microsoft.public.dotnet.security)
    • Re: Importing SSL to new server
      ... i've successfully imported the certificate ... > imported certificates don't show up. ... > them to another Certificate store? ... >>Local computer store... ...
      (microsoft.public.inetserver.iis.security)
    • Re: SMS 2003 SP1 Client Install Problem or Policy Retreival Problem?
      ... > Failed to find running shell process ... >> It is possible that the crypto store has somehow been corrupted. ... >>> The MP is setup and thousands of other clients have access. ... >>> Failed to find the certificate in the store, ...
      (microsoft.public.sms.admin)