Re: Help Please! IPSecurity Policy

From: Tony (indengr@yahoo.com)
Date: 08/29/02


From: "Tony" <indengr@yahoo.com>
Date: Thu, 29 Aug 2002 12:24:27 -0700


Hi,
  The certificate is in local machine/Trusted root
certification authorities. It is also in local
machine/personal store. How do I find out if the CA is
Enterprise CA or standalone CA.
  I configued this CA on a windows 2000 domain for the
whole domain. Its on a domain controller.

Thanks-awaiting your response.

tony

>-----Original Message-----
>1) Is the certificate in the Local machine\Personal store
>2) The certificate may need to have the IPSEC IKE policy
>I can explain how to configure this if you tell me if
the CA on machine A is
>an Enterprise CA or Standalone CA
>
>--
>This posting is provided "AS IS" with no warranties and
confers no rights.
>Use of any included samples is subject to the terms
specified at
>http://www.microsoft.com/info/copyright.htm"
>"tony" <indengr@yahoo.com> wrote in message
>news:9a9701c24f05$9c7fd7d0$35ef2ecf@TKMSFTNGXA11...
>> Hi,
>> I'm having a weird certificate problem on one of my
>> windows 2000 advanced server machines. It is a domain
>> controller. Lets call it Machine A.
>> I'm using this to dial up to a different server (vpn
>> server) in the internet. Lets call this Machine B.
This
>> VPN Server is also a windows 2000 domain controller and
>> runs Certificate authority.
>>
>> As I'm using Machine A to VPN into machine B, I have
to
>> configure ipsecurity policy on this machine A. So I
do
>> the following:
>>
>> 1) I start internet explorer and type
>> http://MachinA/certsrv/ to request a certificate from
the
>> certificate authority. I successfully get a
certificate
>> and install it. Its for all purposes including client
>> authentication. I checked the certificates list and
the
>> certificate is installed in the trusted root
certication
>> authorities.
>>
>> 2). I start MMC and add the 'IpSEcurity policy
management'
>> snapin for the local machine.
>>
>> 3). I right click and select ' create ip security
policy'
>> and then the wizard pops up. After entering a name,
it
>> prompt to select an authentication method. And I
>> select 'Use a certificate from a certificate authority'
>> and try to browse to select the certificate I generated
>> from Machine B. I don't see the certificate at all.
But
>> I see all other certificates from the root
certification
>> authority.
>>
>> why doesn't my ceritificate show up? If I use
>> ceritificates snap-in or internet explorer option -
>> certificates, i can see it. Rememember the
certificate is
>> issued for all purposes.
>>
>> I'm not sure what I'm doing wrong here. Help!
>>
>> thanks
>> tony
>>
>>
>>
>>
>
>
>.
>



Relevant Pages

  • Re: is http mail secure?
    ... you could set up your own certificate authority on your domain and then ... Authority to all of you clients to add to their trusted root ... Some may have their Certificate Authority preloaded in IE (or ... P.S.S - a certificate is a public encryption key used by your browser to ...
    (microsoft.public.exchange.connectivity)
  • Re: Certificate error - active sync exchange 2003
    ... If the certificate on the exchange server is valid and has been issued from ... an internal certificate authority you will need to add the root certificate ... certificate authority then use the "Enroller" program located on the 6700 to ...
    (microsoft.public.pocketpc.activesync)
  • Re: Remote Web Workplace Stopped Functioning
    ... When I changed our certificate, I found that I had to go into add/remove ... components and make sure certificate authority was enabled. ... SBS and inside the ISA server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Can you really trust the police?
    ... a trusted certificate authority. ... private corporations called certificate authorities. ... non-profit certificate authority. ... Corporate CAs have their root certificates ...
    (uk.transport)
  • Removed MS Cert Authority
    ... hours and will add an entry in the App log and System log. ... Domain Controller certificate. ... Silverback is the name of the Certificate Authority I installed for testing ... Authority and removed the server from the domain approx 3 months ago. ...
    (microsoft.public.windows.server.active_directory)