Strange SSL problems

From: news.comcast.giganews.com (nomadpgmr_at_comcast.net)
Date: 11/13/03


Date: Thu, 13 Nov 2003 01:49:58 -0800

I recently generated a CSR for a customer.
I received the certificate back from Thawte and installed it without any
problems.
I then checked the site to make sure it could be viewed using https
I got a DNS error, even when trying to view the site using the IP address

I started digging around and tried a few things.
I could view the certificate and it looked good from within IIS.
The screen said that there was a private key present.

I tried to export (backup the certificate), but when I did so it said no
private key was present.

I determined that the MMC was failing to read a key file from:
C:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys

I compared the permissions on this directory to the permissions on another
server. The permissions were set correctly.

I then generated another CSR on the 1st server and noted that no file was
created in
C:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys

Generating an identical CSR on the 2nd server and found the system did
create a key file in
C:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys

Anyone have any idea as to why this would work correctly on oen system and
not on another?

I can always generate the CSR and install the certificate on another system
and move it over, so I have a workaround. What I would like to know is why I
am seeing what I am seeing.

Thanks,
Roger



Relevant Pages

  • Re: Suppressing security dialogs when app opens
    ... "Adding the above two keys to the install makes the runtime install ... I'm not comfortable altering the security mechanism of a machine without the user's knowledge ... ... Because a digital certificate you create yourself isn't issued by a formal certification authority, ... Microsoft Office will only trust a self-signed certificate on a computer that has the private key for that certificate ...
    (comp.databases.ms-access)
  • Re: Certificates on Floppy Disk?
    ... > give you the option to install this certificate which you want to do. ... > unselect enable strong protection as user will have to enter private key ... > personal folder for the computer store and select import and then browse ...
    (microsoft.public.windows.server.security)
  • Re: Adding certificate using X509Store
    ... The problem was that the private key of the ... \par certificate wasn't being persisted, ... \par> Microsoft MSDN Online Support Lead ... \par> When I press the corresponding "Install" button in my app I see the ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: how to enable that private key can be exported
    ... Once you download and install this certificate to e.g. your PC, ... also be able to export the private key. ...
    (microsoft.public.windows.server.security)
  • Re: Can a Windows service find a certificate ?
    ... If you wish to use a certificate and its corresponding private key you will ... the service account). ... Or beter: Which user can install ...
    (microsoft.public.platformsdk.security)