Re: X509 certificates

From: Eduard Koller [MSFT] (eduardk_at_online.microsoft.com)
Date: 07/19/05

  • Next message: Roger Abell: "Re: What would happen if a solo W2K DC were to crash, and the data would be protected with NTFS?"
    Date: Mon, 18 Jul 2005 18:42:50 -0700
    
    

    What do you mean by "JRE's cert store"?
    You may need to add the issuer CA's certificate to your client's NTAuth
    store.

    -- 
    Eduard Koller[MS]
    This posting is provided "AS IS" with no warranties, and confers no rights.
    Use of included script samples are subject to the terms specified at 
    http://www.microsoft.com/info/cpyright.htm
    "ap70" <ap70@discussions.microsoft.com> wrote in message 
    news:C5A64E77-5484-41D9-96E6-752E5273DB6D@microsoft.com...
    > Hi there,
    >
    > How do i create X509 certificates for server authentication. I want to use
    > JNDI API to access data from AD using SSL. Here is my scenario.
    >
    > 1. Win 2003 box on a private domain 'mydomain.net'.
    > 2. Active directory domain controller is obviously has
    > FQDN=<myhost>.mydomain.net
    > 3. My certification authority is set up with enterprise root as
    > 'my-enterprise (i tried standalone CA also).
    > 4. I followed the steps on
    > http://support.microsoft.com/default.aspx?scid=kb;en-us;321051#XSLTH3154121122120121120120
    > but my client can not trust the certificate. It throws an exception -
    > "javax.net.ssl.SSLHandshakeException:
    > java.security.cert.CertificateException: Could not find trusted 
    > certificate"
    > 5. My client is on the same machine.
    > 6. i am using 'keytool' to import the certifcate into my JRE's cert store.
    >
    > Any help will be appreciated.
    >
    > Thanks
    > Anup 
    

  • Next message: Roger Abell: "Re: What would happen if a solo W2K DC were to crash, and the data would be protected with NTFS?"

    Relevant Pages

    • RE: SmartCard Your credentials could not be verified.
      ... This posting is provided "AS IS" with no warranties, ... SmartCard Your credentials could not be verified. ... | In the event log of the client PC i get "The client has failed to ... | the Domain Controller certificate for %servername%. ...
      (microsoft.public.windows.server.general)
    • Re: WinInet/AfxInet -- authenticate server
      ... If the name is not x.y.com the connection attempt ... >>> certificate with different name? ... If the malicious *server* admin can get to the ... > other hand the *client* cert store is trusted then you have no problem. ...
      (microsoft.public.win32.programmer.networks)
    • Re: Is it possible to force IIS to accept any client ssl certificate?
      ... This posting is provided "AS IS" with no warranties, ... > Does anyone know if it is possible to tell IIS to accept any client ... > certificate. ... > filter and tell IIS to accept the connection and get a hold of client ...
      (microsoft.public.platformsdk.security)
    • Re: Key length question
      ... This posting is provided "AS IS" with no warranties, and confers no rights. ... > certificates for our clients using MS Certificate Server..But I guess it's ... >> the key length is determined by the OS on your client machine. ...
      (microsoft.public.security)
    • Re: Is it possible to force IIS to accept any client ssl certificate?
      ... This posting is provided "AS IS" with no warranties, ... > Does anyone know if it is possible to tell IIS to accept any client ... > certificate. ... > filter and tell IIS to accept the connection and get a hold of client ...
      (microsoft.public.inetserver.iis.security)

  • Quantcast