Requesting a certificate for a Cisco PIX

From: Martin Jakob (Martin.Jakob_at_nospamMicronas.com)
Date: 10/22/03


Date: Wed, 22 Oct 2003 16:28:44 +0200

Hello,

I am trying to request a certifcate for a Pix Firewall via SCEP. The CA is a
Windows 2000 Enterprise Root CA. So far i didn't have success. In the
Eventlog of the CA is the following entry:
"Certificate Services denied request 8315 because Access is denied.
0x80070005 (WIN32: 5). The request was for CN=pix+
OID.1.2.840.113549.1.9.2=pix. Additional information: Denied by Policy
Module".

In Technet i found following passage:
"Because enterprise certification authorities use Active Directory to
determine the identity of the requester and to determine whether the
requester has the security permissions to request a certificate of the type
that they specify, the CA automatically determines whether a requester is
authorized to receive the certificate requested."

So, is it possible to enroll this certificate to the Pix, by adding the
Device to the Active Directory? Any hints/tips are welcome.

--
Martin


Relevant Pages

  • Re: Computer and User Certificates Issues
    ... Enrollment of User Certificates using the custom v2 User Certificate Template ... I can NOT request the custom v2 Computer Cert nor the included v1 no ... Concerning permissions, these are the exact permissions I am using now: ...
    (microsoft.public.security)
  • Re: Cannot request computer certificate.
    ... request a computer certificate for about 9 months. ... and verify that you can get a computer/server certificate from it. ... List of NetBt transports currently bound to the Redir ... DNS Host Name: srvr3.domain.com ...
    (microsoft.public.windows.server.security)
  • RE: SIMple SSL question ??
    ... OK - i would also delete a cert request file lying around. ... But a certificate is a pub key + extra info. ... That said - if someone compromises the server he will also find a way to retrieve the private key. ... traffic between the initial web server and the client. ...
    (microsoft.public.dotnet.security)
  • Re: how can we restrict what certificate WSE will use?
    ... the valid x509 certificate which is used to identify him'. ... X509SecurityTokenManager to verify the request is from a trusted client. ... the problem is that he can not passed the authentication (suppose we ... > decrypte and signature validation process. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Web Certificate Enrollment security problem
    ... Enrollment works only with the NetBIOS Name and not with the FQDN. ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ... access auditing and logging "issue and manage certificate requests" on ... Have seen that there is a component "Certsrv Request" when launching ...
    (microsoft.public.security)