Re: Windows 2003 with third partu CA

From: David Cross [MS] (dcross_at_online.microsoft.com)
Date: 10/30/04


Date: Sat, 30 Oct 2004 11:22:13 -0700

one of these three articles should help you track down what is missing from
your scenario and causing the failure:

         Guidelines for Enabling Smart Card Logon with Third-Party
Certification Authorities (Q281245):
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q281245

ˇ Requirements for Domain Controller Certificates from a Third-Party
CA (Q291010):
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q291010

ˇ How to Import a Third-Party Certificate into the NTAuth Store
(Q295663): http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q295663

-- 
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
http://support.microsoft.com
"S. Pidgorny <MVP>" <slavickp@yahoo.com> wrote in message 
news:uJ7W0vZvEHA.2564@TK2MSFTNGP12.phx.gbl...
> You probably have seen the guidelines:
> http://support.microsoft.com/?id=281245. I'd suggest that you'll have to 
> try
> HTTP and/or FTP CRL distribution point, as LDAP schema for CRL is not
> standartised, as far as I remember.
>
> -- 
> Svyatoslav Pidgorny, MVP, MCSE
> -= F1 is the key =-
>
>
>
> "Lorenzo Soncini" <lorenzo_soncini_technoservice_com> wrote in message
> news:OKTx3AZvEHA.1564@TK2MSFTNGP09.phx.gbl...
>> Hi,
>> I have implemented a smart card logon on Windows 2003 domains and all 
>> work
>> fine.
>>
>> Now I need to use an external CA for authentication based on SUN Solaris
>> system. I have make the configurations but when I try the logon the 
>> System
>> return an error who say:
>> "The system could not log you on. The smartcard certificate used for
>> authentication was not trusted."
>>
>> I have added the CDP point in the proprieties of the CA as LDAP server 
>> but
>> don't work.
>>
>> How can I tel Windows 2003 to use an external LDAP server for checking 
>> the
>> revocation of the Certificate?
>>
>> Sorry for my english and thanks for any help
>> Lorenzo Soncini
>>
>>
>
> 


Relevant Pages

  • SSL/TLS hell
    ... TLS/SSL certificates are supposed to work? ... remote LDAP server to which I successfully got connected to without ... Can't contact LDAP server, even if I specify the "-v" ... a certificate with the CN set to the hostname I'm trying to connect to, ...
    (comp.os.linux)
  • SSL/TLS hell
    ... TLS/SSL certificates are supposed to work? ... remote LDAP server to which I successfully got connected to without ... Can't contact LDAP server, even if I specify the "-v" ... a certificate with the CN set to the hostname I'm trying to connect to, ...
    (comp.unix.programmer)
  • Generate a Self-Signed Certificate for LDAP server.
    ... I have problem to set up ssl for LDAP server. ... These are the steps for generate a Self-Signed Certificate for LDAP server. ...
    (comp.unix.solaris)
  • Re: I need help with LDAP and Evolution
    ... > What I did to solve the problem was to download the CA certificate from ... > method for creating the checksum symlinks, but I don't know it off the ... And I succeeded in connecting, updating the ldap server on my LOCALHOST, ...
    (Fedora)
  • Re: Need help configuring Wireless Connection profile
    ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless ... Vaillancourt,4155,1,4154,Use Windows authentication for all ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)