RE: Certificate request

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Ray Fong [MSFT] (rayfong_at_online.microsoft.com)
Date: 08/02/04


Date: Mon, 02 Aug 2004 19:43:55 GMT

It looks like you need a cert just for your own webserver. In this case,
you can pick Stand-alone Root CA for better security.
To make things even more simple, you can use IIS Reskit SelfSSL.exe to
create your own cert without Certificate Server.

For example, the URL you wants to be www.microsoft.com, and the Identifier
for the website is 123456, all you need to do is run:

selfssl.exe /N:CN=www.microsoft.com /K:1024 /V:180 /S:123456 /P:443

This will get a cert created. If the website is going to be access by the
rest of the world, then you really should buy a commercial cert.

IIS 6.0 Resource Kit Tools
http://www.microsoft.com/downloads/details.aspx?FamilyID=56fc92ee-a71a-4c73-
b628-ade629c89499&DisplayLang=en

Anyway, if you have CertServer installed, when you generate a cert in IIS,
you should have the option "Send the request immediately to an online
certification authority" which will auto generate and install the cert for
you in iis.

Ray Fong
Microsoft SBS Product Support

This posting is provided "AS IS" with no warranties, and confers no rights.

>
>Thanks Ray for your help.
>
>When adding the certificate server, it prompt me to select
>a CA Type (enterprise root CA, Enterprise subordinate CA,
>Stand-alone root CA, or stand-alone subordinate CA.)
>
>It is not clear to me which option to select. This server
>is hosted at an ISP, and runs a website that needs to run
>secure/ for which I need to generate a certificate request.
>
>Also, once the certificate server is installed, do I still
>use the MMC certificate snap-in to generate the request?
>
>Thanks again.
>
>Peter
>>-----Original Message-----
>>Do you have Certificate Server installed (Add/Remove
>Program -> Windows
>>Componenet)? If you want additonal cert (other than the
>one created by the
>>wizard which doesn't use Certificate Server), you need to
>get it installed.
>>
>>Ray Fong
>>Microsoft SBS Product Support
>>
>>This posting is provided "AS IS" with no warranties, and
>confers no rights.
>>
>>>
>>>I am trying to generate a new certificate request using
>>>MMC in SBS2003, and get the following error:
>>>
>>>The wizard cannot be started because of one of the
>>>following conditions:
>>>-There are no trusted certification authorities (CAs)
>>>availabe.
>>>- You do not have the permission to request certificates
>>>from the available CAs.
>>>- The available CAs issue certificates for which you do
>>>not have permissions.
>>>
>>>I am logged on as the administrator. What am I doing
>wrong.
>>>
>>>Any suggestions are appreciated.
>>>
>>>Peter
>>>
>>
>>.
>>
>



Relevant Pages

  • IIS does not listen on ssl port
    ... I have purchased a certificate for verisign and installed on IIS 5. ... I have reviewed the steps on how to install the cert and then set the ... website to require SSL but i do not want to do that until i know i ...
    (microsoft.public.inetserver.iis.security)
  • Re: Enterprise CA help
    ... web pages with standalone CAs. ... > install a cert for SSL for OWA traffic. ... I decided to install Enterprise CA on a domain controller, ... > problem is the server CA is on does not run IIS. ...
    (microsoft.public.win2000.security)
  • Re: Exchange 2003 Cluster and HTTPS OWA
    ... You can't import a .cer format using IIS. ... >From your other IIS server, you need to export it to .pfx format (this ... > I have a copy of the cert. ... I can dbl click it an install but when I use ...
    (microsoft.public.exchange.admin)
  • Hardware SSL (BIG-IP) / IIS Detection
    ... We run BIG-IP from F5 Networks for traffic management and install our SSL ... Is there a way to setup this environment so that IIS knows that the ... incoming request was actually decrypted by the BIP-IP? ... normally when a cert is installed on IIS? ...
    (microsoft.public.inetserver.iis.security)
  • Re: PKI / SSL
    ... >> services and employ our own certificate server. ... >> This certificate server for now will only be used to secure web pages ... >> warning message about the cert was not issued by a company that was chosen ... >> and install the cert into my browser and not get prompted again. ...
    (microsoft.public.inetserver.iis)