computer certificates for L2TP/IPSec

From: Tony Su (anonymous_at_discussions.microsoft.com)
Date: 07/08/04


Date: Thu, 8 Jul 2004 09:21:44 -0700

http://www.isaserver.org/img/upl/vpnkitbeta2/webenrollenter
prise.htm

Tony Su

>-----Original Message-----
>Hello all,
>
>After fours days of pulling my hair out I thought I would
>ask the experts...
>
>I am trying to setup a secure VPN connection using
>L2TP/IPSec... I am running (all on one box for now)
>SBS2003 standard, IAS, CA, DNS, RRAS....
>
>I can enable remote access IPsec policies and have
managed
>to get certificates on the client machine to work for
>IPSec... what I cannot seem to accomplish is to get a
>computer certificate to install that will work for the
>L2TP tunnel...
>
>I can install certificates through the CA web services
>interface but cannot get a Computer certificate to list
as
>a option.... when I try to request certificates manually
>through the MMC cert snap-in I get "the certification
>authority cannot be reached. Please try again later".
>when on the server I can use the certutil.exe ping and
>ping admin verbs and get succesful responses...
>
>oh the client machine is a fresh install w2k with all the
>patches installed... it connects when I do not reqire
>L2TP tunnel type...
>
>here's hoping someone can help me!
>Thanks!
>Gered
>.
>



Relevant Pages

  • Re: RECOVERING MY ENCRYPTED HD FROM DEAD WINDOWS 2000
    ... certificates were probably only stored on the reinstalled ... file encryption key - different for each file, ... document formats have some standard bytes in - once matched ... The install wouldn't ...
    (microsoft.public.windowsxp.security_admin)
  • computer certificates for L2TP/IPSec
    ... I can install certificates through the CA web services ... interface but cannot get a Computer certificate to list as ... ping admin verbs and get succesful responses... ...
    (microsoft.public.windows.server.sbs)
  • Re: Run Fax Service under a different User Account gives "Win32 Error Code: 1307" error
    ... I've been trying to do that, but I can't seem to get the certificates to ... I wouldn't want to give the "Network Service" account access to the ... encrypted files because then any service running under the Network Service ... know of any way to install the certificate for the Network Service user. ...
    (microsoft.public.win2000.fax)
  • Re: IAS / RRAS
    ... Install Certificate services ... Configure the VPN connectoid and set it for l2tp connections? ... So you may want to try to do without the IAS server until problems ... > are resolved to rule it out as a problem.As far as certificates, ...
    (microsoft.public.windows.server.networking)
  • Re: CA auto-enrollment policies with Windows 2003
    ... Yes you need to have your enterprise CA installed on Windows 2003 Server ... issue computer certificates to domain computers. ... > existing domain controllers we really don't want to also install IIS on ...
    (microsoft.public.windows.group_policy)