Re: Request a new certificate



On Sat, 10 Nov 2007 14:45:47 -0800, Aaron <bikefaster@xxxxxxxxx>
wrote:

I'm running Windows Server 2003 SBS and trying to export an SSL
certificate of a web site. I go into the MMC, add the Certificates
snap-in, select Computer Account, Local Computer, and expand the
Personal Certificates. After selecting the appropriate certificate,
choosing export, it does not give me the option to click, "Yes,
export
the private key." It is my understanding that this will happen if the
key has already been exported.

Therefore, it should work if I requested a new certificate for the
site. I then open the IIS manager, navigate to the web site, and
choose Server Certificate under Directory Security. My options are to
either renew, remove, or replace the current certificate. What
exactly
should I do? Am I heading in the correct direction? Any assistance
would be greatly appreciated.

What I do normally is in IIS backup the certificate to a .pfx file
which will also back up the private key also. This can be done
through the wizard. Only last week I got burned by trying to renew a
certificate using the original certificate request, and it worked up
until the point of replacing the certificate in the IIS settings,
wherein I lost the private key, and neither certificate worked,
causing me to have to go through a re-issue process (as I had not
backed up the PFX file in that instance).

Andrew.
.



Relevant Pages

  • RE: Secure web site access and PKI Certs
    ... The 'Enable Strong Private Key" option is to ensure non-repudiation is ... sent signed with the senders public key and encrypted with the senders ... Secure web site access and PKI Certs ... If the PKI certificate is installed on the local ...
    (Security-Basics)
  • [NT] Flaw in Certificate Enrollment Control Could Allow Deletion of Digital Certificates
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Certificate Enrollment Control, the purpose of which is to allow web-based ...
    (Securiteam)
  • Re: Embedding Simple MFC GUI app into website
    ... The problem with security is that so many people say "it doesn't matter". ... particular technology is "evil" goes beyond common sense and increases ... Since you must obtain a certificate for code signing from the trusted ... use it for a general purpose web site as we have all discussed, ...
    (microsoft.public.vc.mfc)
  • Re: Embedding Simple MFC GUI app into website
    ... particular technology is "evil" goes beyond common sense and increases ... ActiveX, in particular, is an antipattern for security. ... Since you must obtain a certificate for code signing from the trusted ... use it for a general purpose web site as we have all discussed, ...
    (microsoft.public.vc.mfc)
  • RE: Publishing Companyweb for external access on SBS2003 R2 With I
    ... would like to show out the recommended steps to publish companyweb. ... To publish companyweb in ISA Server 2004, we can simply run the CEICW ... "Allow access to only the following Web site services from the internet" ... On the "Web Server Certificate" page, choose to create a new Web server ...
    (microsoft.public.windows.server.sbs)

Loading