Re: Standalone Subordinate Certificate Server Problems
From: adrian cristea (adriancristea@yahoo.com)
Date: 07/30/02
- Next message: Scott: "prevent local admin users seeing domain user list ?"
- Previous message: Lee Steventon: "Kerberos Security - How to switch off"
- In reply to: D. Cross [MS]: "Re: Standalone Subordinate Certificate Server Problems"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "adrian cristea" <adriancristea@yahoo.com> Date: Tue, 30 Jul 2002 14:27:50 +0300
thank you for answering me.
more details:
the first time that i try to install the certificate from the root (on the
child) i get the message "The format of the specified computer name is
invalid." If i try again it says "The data is invalid. 0xd (13)".
i followed this document to install and configure the two CA servers:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q271386
i installed stand-alone, not enterprise CAs.
the child CA is an advanced server updated with all the patches
(a.f.a.i.k.). the root CA is also updated with all the necessary patches.
other (new installed and fully patched) server (not advanced) can install
the certificate from root CA and start the certificate service. the servers
have internal dns names; the internal dns domain isn't registered as a
Internet domain name.
i modified the CRL distribution point and Authority Information Access of
root CA to an external DNS name address (this address has an Internet IP
address, assigned to an external interface on a ISA server; ISA server is
using Web Publishing to publish the web pages with .crt and .crl files of
the root and child CAs, in diferent folders/pages). but i tried also with
internal ip addresses as CRL distribution point and Authority Information
Access and is not working either. i deactivated all other locations (ldap,
share, etc.)
below is the request from child to root:
-----BEGIN NEW CERTIFICATE REQUEST-----
MIICDjCCAbgCAQAwgaoxIDAeBgkqhkiG9w0BCQEWEWFkbWluQG1hdGhlc2lzLnJv
MQswCQYDVQQGEwJSTzESMBAGA1UECBMJQnVjdXJlc3RpMRIwEAYDVQQHEwlCdWN1
cmVzdGkxGjAYBgNVBAoTEUZ1bmRhdGlhIE1hdGhlc2lzMRowGAYDVQQLExFGdW5k
YXRpYSBNYXRoZXNpczEZMBcGA1UEAxMQd3d3Mi5tYXRoZXNpcy5ybzBcMA0GCSqG
SIb3DQEBAQUAA0sAMEgCQQDEW4RJthYM7hFo3752PTcw35WOHc8dF2b8fghAmE/k
w1/DAF0SMKZFEVJZW6uf3lDqHQjfIrz9k6XGu71iMnznAgMBAAGggacwKQYKKwYB
BAGCNw0CAzEbFhk1LjAuMjE5NS4yLlNlcnZpY2UgUGFjayAyMHoGCisGAQQBgjcC
AQ4xbDBqMBAGCSsGAQQBgjcVAQQDAgEAMB0GA1UdDgQWBBTS66eiI+nxqH5k6BtE
LAeEk2qgtDAZBgkrBgEEAYI3FAIEDB4KAFMAdQBiAEMAQTALBgNVHQ8EBAMCAUYw
DwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQUFAANBAGXKz+c/1uphU911Tpik
Y20NyXdvK1rK72VXc4SNwlXhcNNABUTOcfYCoVIYR+6NCpCBKAQ2wdunnqHZ2BWA
v20=
-----END NEW CERTIFICATE REQUEST-----
is there an utility to investigate the request? how can you do that?
thanks.
- Next message: Scott: "prevent local admin users seeing domain user list ?"
- Previous message: Lee Steventon: "Kerberos Security - How to switch off"
- In reply to: D. Cross [MS]: "Re: Standalone Subordinate Certificate Server Problems"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|