RE: SSL configuration for SQL server

From: Kevin McDonnell [MSFT] (kevmc_at_online.microsoft.com)
Date: 01/30/04


Date: Fri, 30 Jan 2004 01:32:27 GMT

Make sure you check the following Key Options when you request the
certificate:

Store certificate in the local computer certificate store
Stores the certificate in the local computer store
instead of in the user's certificate store. Does not
install the root CA's certificate. You must be an
administrator to generate or use a key in the local
machine store.

To verify that the cert is installed you can use the following Capicom
script

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/security/Se
curity/getting_ready_to_use_capicom.asp

To get a listing of the certs installed on the machine local store
cscript ctool.vbs /list /store my /storeloc lm /verbose >MachineCerts.txt

Thanks,

Kevin McDonnell
Microsoft Corporation

This posting is provided AS IS with no warranties, and confers no rights.



Relevant Pages

  • Re: PEAP error message with CA and IAS
    ... drop from the personal store to the local machine ... I'll try exporting the cert now.... ... >> The certificate appears to be in the Local Computer ... >> Of the 10 stores in each of Local Computer and Current ...
    (microsoft.public.internet.radius)
  • Re: Active Directory Federation Services
    ... that is associated with their profile and the machine itself has a store. ... Just wanted to let you know that I got the cert problem fixed. ... the user certificate store. ... FSP was looking for certs in the local ...
    (microsoft.public.windows.server.active_directory)
  • Re: Accessing certificate store from ASP.NET web project
    ... the cert must be in the local computer/personal) store - it will then open ... Have a look at the source code to open the right cert store... ... One of the locations requires a x509 certificate in order ... different user context than my vb.net web project. ...
    (microsoft.public.dotnet.security)
  • Re: Certificate Installation Question
    ... look for a tool called Certificate manager tool: ... > to the correct store? ... > this cert to? ... >>> the Local Computer into Trusted CA and everything works fine. ...
    (microsoft.public.internet.radius)
  • Re: Importing SSL to new server
    ... i've successfully imported the certificate ... > imported certificates don't show up. ... > them to another Certificate store? ... >>Local computer store... ...
    (microsoft.public.inetserver.iis.security)