Certificate Server

From: Mike Benner (mbenner@airmail.net)
Date: 10/02/02


From: "Mike Benner" <mbenner@airmail.net>
Date: Tue, 1 Oct 2002 23:11:58 -0700


I'll hazard a guess. The answer depends on wheather or
not you've installed a root CA or a subordinate CA. I'm
going to guess you have a subordinate CA and need a
certificate installed so that the services will operate
properly. To see if this might be the case open the MMC
CA snapin to see if the CA has a green check mark next to
it's name. If it doesn't you may just need to generate a
certificate request for the CA. To do this right click on
the name of the subordinate CA. This will give you a menu
with an option to request a certificate, either from a
machine that's online or from a machine that's offline.
Follow the wizards instructions for generating a request
file. The request in this file can be pasted into an
advanced certificate request form if you're running a
Microsoft CA, or if you want to get a certificate from a
third party such as Verisign you can past this request
into their request form. Once you have the new cert go
back to the MMC Certificate snapin and install the new
certificate. At this point you should be able to start
the certificate services and request new certs.

If this is a root CA you'll need to generate a self signed
certificate and install that on the macine.
Hope this helps. If this is not what you needed you can
contact me at mbenner@airmail.net.

One final thought. For security and operational reasons I
wouldn't run anything on a CA other than the CA software.
If there's a way you can afford to let this machine be a
CA and only a CA you'll be better off.

Regards
Mike Benner
>-----Original Message-----
>I have recently installed a stand alone CA on a Windows
>Update Server for our internal network. This box is a
>Win2k server with SP3 installed. When a user does a
>request for a new certificate one recives the error:
>
>Failed to create 'CertificateAuthority.Request' object.
>
>I have removed and reinstalled the certificate services
>and replaced SP3 on the box after the installs. I still
>recieve this error. Before I could get this far I had to
>install q323172 to get it to process the request. I have
a
>feeling that the patch is what is keeping it from working
>but not going to bet the farm on it. Has anyone had this
>problem and fixed it. Please let me know all ideas are
>welcome at this point.
>
>Thanks
>
>Chris Hankins, CCNA,MCP,MCSA
>LAN Administrator
>Nexiq Technologies, Inc.
>hankins@nexiq.com
>.
>



Relevant Pages

  • Re: Change public domain name for E-mail and Web on SBS2003
    ... self-cert from everything while the request was being processed. ... I need to change the e-mail addresses, and the SSL certificate to match ... just run the Connect to the Internet Wizard ... request and install the new SSL Cert? ...
    (microsoft.public.windows.server.sbs)
  • RE: 3rd Party Certificate Pending Request not found
    ... This request may be canceled. ... After much trial and tribulation the 3rd party GoDaddy certificate started ... You are attempting to install a certificate that does not match the private ... If you have a backup of the private key, you can install the certificate via ...
    (microsoft.public.windows.server.sbs)
  • Re: Win2003 PKI : Subordinate CA certificate parameter
    ... You need to change the CAPolicy.inf on the subordinate CA. CAPolicy.inf is used during the enrollment process and the request and its contents depends on the file. ... the request already contains key usage 0x86 described as above and the root CA is issuing a certificate based on that request. ...
    (microsoft.public.windows.server.security)
  • Re: Installing an existing GoDaddy SSL on another SBS box....
    ... Certificate' and then 'Assign an existing certificate'. ... I've got a functional GoDaddy SSL cert installed and working on my ... vanilla install so far. ... I got an error that there was no pending request for the ...
    (microsoft.public.windows.server.sbs)
  • Re: Unable to install Godaddy cert on SBS R2 Standard box
    ... When you receive the file from Godaddy it is in a .crt file and Windows is looking for a .cer. ... "Please create a new request,and request for a new certificate from ... Godaddy(issue a new certificate),then install the new certificate. ...
    (microsoft.public.windows.server.sbs)