2003 Enterprise CA, MSCEP - 0 length cert message on cisco 837 rou

From: Peter Arians (PeterArians_at_discussions.microsoft.com)
Date: 04/29/05


Date: Thu, 28 Apr 2005 23:14:01 -0700

Hello Everyone,

I'm trying to use MSCEP on a 2003 Enterprise CA to request a certificate for
Cisco 837 router. When I run the cisco command "crypto ca authenticate
TRS-AD-CA" the router comes back with a message "% Error in receiving
Certificate Authority certificate: status = , cert length = 0" which
indicates that my 2003 CA is not sending anything back for the request.

I can successfully request a certifcate from this router when I connect to a
2000 Standalone CA but my new 2003 Enterprise CA is not working correctly. I
initially had problems with the 2003 Cert Server installation as IIS was
already installed on the server before DCPROMO was run however I followed the
Microsoft Knowledge base article (332097) and corrected the security
permisions. When I install MSCEP I can see that the CA issues an "Exchange
Certificate" and "CEP certificate" but there is still something wrong when
trying to get the router to request a cert.

I think the CA is okay as I can request other Certs from a web browser etc.
and I see my AD Domain servers have automatically requested and received
certificates however my MSCEP is failing.

Does anyone have any ideas where to look to resolve this problem as I can't
find any similar problems on the internet.

Thanks in advance,

Peter Arians.



Relevant Pages

  • Re: 2003 Enterprise CA, MSCEP - 0 length cert message on cisco 837 rou
    ... Just worked for me on Friday with Windows 2000 Enterprise CA and Nokia VPN. ... I would be looking at alternative way of delivering the CA certificate to ... > Cisco 837 router. ... > indicates that my 2003 CA is not sending anything back for the request. ...
    (microsoft.public.security)
  • Re: Cert Server Denying Certs requests - Event ID 21: The certificate is revoked
    ... I'm requesting new certificate using mscep. ... I'm generating new keys set on router side, getting CA certificate, ... At end on router side I receive message that enrollment was rejected by CA, ... > How are you trying to request it? ...
    (microsoft.public.win2000.security)
  • Re: Cert Server Denying Certs requests - Event ID 21: The certificate is revoked
    ... I can't be of much more help as I have never used mscep to request a cetificate ... The revoked certificate error is puzzling in that a revoked certificate ... > I'm generating new keys set on router side, getting CA certificate, authenticating ...
    (microsoft.public.win2000.security)
  • Re: 2003 Enterprise CA, MSCEP - 0 length cert message on cisco 837 rou
    ... >> I'm trying to use MSCEP on a 2003 Enterprise CA to request a certificate ... >> indicates that my 2003 CA is not sending anything back for the request. ... >> initially had problems with the 2003 Cert Server installation as IIS was ...
    (microsoft.public.security)
  • Re: Computer and User Certificates Issues
    ... Enrollment of User Certificates using the custom v2 User Certificate Template ... I can NOT request the custom v2 Computer Cert nor the included v1 no ... Concerning permissions, these are the exact permissions I am using now: ...
    (microsoft.public.security)