RE: Certificate Woes - Problem with CA
- From: briandel@xxxxxxxxxxxxxxxxxxxx (Brian Delaney [MSFT])
- Date: Tue, 07 Nov 2006 17:18:07 GMT
Hi,
You're absolutely right, we were thinking of different methods. I was
referring to submitting the request to an online CA by using IIS. This
will submit the request directly to the enterprise CA of your choice
without the need to use the web interface.
What I would like you to do as well is run a few diagnostic commands on the
CA you are trying to issue the Web Server certificate from and post the
results.
certutil -template -v > alltemplates.txt
certutil -catemplates -v > allpublished.txt
dsacls "CN=WebServer,CN=Certificate Templates,CN=Public Key
Services,CN=Services,CN=Configuration,DC=domain,DC=local" > templateacl.txt
For the last command you will need the support tools and you will need to
replace DC=domain,DC=local with the that of your forest root domain.
Hope this helps,
Brian Delaney
Microsoft Canada
--
This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: Certificate Woes - Problem with CA<Pj7tsiv9GHA.768@xxxxxxxxxxxxxxxxxxxxx>
thread-index: AccBwaXfl4mFcaLZRPu4/jmj4rANvw==
X-WBNR-Posting-Host: 209.77.80.2
From: =?Utf-8?B?QWxsaWU=?= <Allie@xxxxxxxxxxxxxxxxxxxxxxxxx>
References: <28B3664A-7FF5-4D09-A416-5DCDFEE5DBEA@xxxxxxxxxxxxx>
<C54D3D57-C9E6-4375-9128-2C95391A125A@xxxxxxxxxxxxx>
<s8rTFDbAHHA.4432@xxxxxxxxxxxxxxxxxxxxx>
Subject: RE: Certificate Woes - Problem with CAwhen
Date: Mon, 6 Nov 2006 08:36:02 -0800
Hi Brian,
I can request the certificate just fine using IIS. The problem happens
I submit the Certificate request to the certificate server. I select the64
base encoded CMC or PKCS #10 certificate request, paste that contents ofif
certreq.txt in the appropriate box, when I try to select the Web server
template, I am never given that choice. I only have User and Basic EFS as
Template choices (and therefore, that is where I am stuck). I am not sure
this helped... maybe we are thinking about different methods ofsubmitting
the certificate request... please let me know (this problem is driving merights.
crazy...)
Thanks,
Allie
"Brian Delaney [MSFT]" wrote:
Hi Allie,
What is the error message that you receive when you attempt to request a
certificate through the IIS console?
Hope this helps,
Brian Delaney
Microsoft Canada
--
This posting is provided "AS IS" with no warranties, and confers no
also--------------------
Thread-Topic: Certificate Woes - Problem with CA<Pj7tsiv9GHA.768@xxxxxxxxxxxxxxxxxxxxx>
thread-index: Acb3jHJ+Cb2rGI4NRnObzHG/npl39g==
X-WBNR-Posting-Host: 209.77.80.2
From: =?Utf-8?B?QWxsaWU=?= <Allie@xxxxxxxxxxxxxxxxxxxxxxxxx>
References: <28B3664A-7FF5-4D09-A416-5DCDFEE5DBEA@xxxxxxxxxxxxx>
Subject: RE: Certificate Woes - Problem with CA
Date: Tue, 24 Oct 2006 09:50:01 -0700
Hi Brian,
Thank you for responding! The template is published and the correct
permissions are set. Requesting the certificate through IIS console
underfails... Let me know if you have any other ideas.Certification
Allie
"Brian Delaney [MSFT]" wrote:
Hi,
Is the Web Server template published on the CA? Go into the
Authority snap-in and ensure you can see the Web Server template
hasCertificate Templates. If it is not in that list then the template
consolenot
Certificatebeen published. To publish right-click and go to New and then
Template to Issue.
Also verify the correct permissions are on the template. In order to
enroll the user requesting the certificate needs Read and Enroll
permissions and then CA issuing the certificate must also have Read
permissions to get to the template.
If all else fails try requesting the certificate through the IIS
choice,rights.
Hope this helps,
Brian Delaney
Microsoft Canada
--
This posting is provided "AS IS" with no warranties, and confers no
the--------------------
Thread-Topic: Certificate Woes - Problem with CAserver.
thread-index: Acbsn9Q2E0m7BLQ2T9OavwZnjH3ggw==
X-WBNR-Posting-Host: 209.77.80.2
From: =?Utf-8?B?QWxsaWU=?= <Allie@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Certificate Woes - Problem with CA
Date: Tue, 10 Oct 2006 12:11:03 -0700
I am trying to Submit a Certificate Request for my new Exchange 2003
I have already created the certificate request but when I try to get
requestpending request accepted by my CA, using the 'submit a certificate
using a base 64-encoded CMC or PKCS #10 file, or submit a ...'
WebI
encounter the following problem: I only have User and Basic EFS aschoices
for Certificate Templates (I need to be able to select Web Serverinstead).
When I go to the CA and select manage the templates, I can see the
toServer
template just fine (the permissions seem correct). I even triedduplicating
it, but can't get either the web server or New web server templates
Idisplay in the Submit a Certificate Request or Renewal Request page.
ondon't
see any errors in the event log of the CA either. The CA is running
servera
untilWindows 2003 Server (Std edition). Also, this process was working
about a month ago just fine... Nothing major has changed in the
thisthinkwith
the exceptions of MS security patches being installed (and I don't
that
installing patches would have broken CA). Has anyone encountered
problem or know of a solution? Thanks in advance.
.
- References:
- RE: Certificate Woes - Problem with CA
- From: Brian Delaney [MSFT]
- RE: Certificate Woes - Problem with CA
- From: Allie
- RE: Certificate Woes - Problem with CA
- Prev by Date: Re: Need hotfix for event id: 8017, where to get it?
- Next by Date: 2003 domain controller problems
- Previous by thread: RE: Certificate Woes - Problem with CA
- Next by thread: RE: User Certificates
- Index(es):
Relevant Pages
|