Re: cert authority

From: Jeff Miller (Jeff_Miller_at_kaplan.com)
Date: 03/17/04


Date: Wed, 17 Mar 2004 16:51:21 -0500

Dmitry,
Any chance that you can explain the reason w2k3 white papers told me to
raise the functinoal level to 2003? I think that is the only difference
between my 2 setups, and the 2003 way it never prompted, it just
automatically verified the cert, where now it can't verify it automatically.
We are just trying this method, and want it to be quicker and easier then
the ones our Linux guys are testing.
"Dmitry Korolyov [MVP]" <d__k@removethispart.mail.ru> wrote in message
news:ukKYHrFDEHA.1544@TK2MSFTNGP09.phx.gbl...
Open the certificates console for your user and check Trusted Root
Certification Authorities store. Is there a certificate of your Enterprise
Root CA? It should be, if your workstation is connected to the same forest
where CA is installed. If not, just install it manually or using GP.

-- 
Dmitry Korolyov [d__k@removethispart.mail.ru]
MVP: Windows Server - Active Directory
"Jeff Miller" <Jeff_Miller@kaplan.com> wrote in message
news:OPDXAnFDEHA.2052@TK2MSFTNGP11.phx.gbl...
Dmitry,
I set this up in a w2k3 test env, followed teh white papers, raise the
domain functional level to 2003 (not sure why but white papers said to, and
the wireless worked like a charm, never prompted to trust cert.
Now that I moved it into my 2k AD, it doesn't seem to trust the cert.  We
want a wireless user to just have it authenticate their domain\user and pwd.
Can you shed any light on this?
Thanks again,
Jeff
"Dmitry Korolyov [MVP]" <d__k@removethispart.mail.ru> wrote in message
news:eu63z5EDEHA.240@tk2msftngp13.phx.gbl...
Place the root CA's cert in Truster Certification Authorities store on your
client computer. This should automatically ensure trust to all downlevel
certificates issued by this CA.
-- 
Dmitry Korolyov [d__k@removethispart.mail.ru]
MVP: Windows Server - Active Directory
"Jeff Miller" <Jeff_Miller@kaplan.com> wrote in message
news:u9nvagEDEHA.2424@TK2MSFTNGP09.phx.gbl...
We have a problem with wireless authentication.  I have a CA setup on a
member server w2k3, IAS on another member server w2k3 (with a cert from the
CA), in an active directory native mode 2000.  The access point is cisco.
We can connect and authenticate properly, however it prompts us to ask if we
trust the certificate.  If we don't click yes quickly, it will fail.
Any ideas on how to automatically trust and verify the cert, or how to
increase the timeout (now about 2 seconds).
Thanks in advance


Relevant Pages

  • Re: cert authority
    ... Open the certificates console for your user and check Trusted Root ... Now that I moved it into my 2k AD, it doesn't seem to trust the cert. ...
    (microsoft.public.win2000.active_directory)
  • Re: [Full-disclosure] HTTP AUTH BASIC monowall
    ... There are a couple of dozen CA certificates shipped with my browser. ... They're certifying that somebody convinced them that the cert ... Anybody who attaches any ... If you don't trust that CA's judgment, you better heave their root cert overboard... ...
    (Full-Disclosure)
  • Re: block certificates from asking if i trust them in IE
    ... > yes, with Windows XP, you should be able to select never trust this cert ... > add it manually to the untrusted certificates folder in the certificates ...
    (microsoft.public.win2000.security)
  • Re: SSL and Client Authentication
    ... First I go on my client and I do a browser request from a CA, ... After issuing a cert. ... install (where I verify that this certification was installed ... > It definitely does not sound like the right way to do client certificates. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Its Either Gonna Be
    ... Nope, stupid certificates like the Microsoft certifications, PMI, ... I worked for Oracle as a senior DBA consultant for four years. ... with a cert. ... She's working as a manager of program managers and managers about 15 to ...
    (rec.sport.football.college)