Re: Certificate Authority Error

From: Brian Komar (bkomar_at_nospam.identit.ca)
Date: 01/13/05

  • Next message: Karl Levinson, mvp: "Re: Any Way to Run Windows 2000 From Read-Only CD?"
    Date: Wed, 12 Jan 2005 17:50:34 -0600
    
    

    How are you generating the request? What toolset are you using. When you
    submit a certificate request to an enterprise root CA, you must include
    tempalte information. Even if the request is generated by a third party
    Web server, you will still have to designate to use the WEb Server
    certificate template as an example.

    If you are using the WEb enrollment, you can designate the certificate
    template on the submission page. See the advanced enrollment whitepaper
    for details on this method:

    http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technolog
    ies/security/advcert.mspx

    Brian

    In article <OLheSIN#EHA.2452@TK2MSFTNGP14.phx.gbl>, jeffpoling@yahoo.com
    says...
    > We are trying to generate a new certifiacte request on a Win2003 Enterprise
    > Root CA. We get the following error:
    >
    > The request contains no certificate template information 0x80094801
    > (-2146875391)
    > Denied by Policy Module 0x80094801, the request does not contain a
    > certificate template extension or Certificate template request attribute.
    >
    > has anyone seen this error before? What are we doing wrong? How can we
    > troubleshoot this?
    >
    > Thanks,
    >
    > Jeff
    >
    >
    >


  • Next message: Karl Levinson, mvp: "Re: Any Way to Run Windows 2000 From Read-Only CD?"

    Relevant Pages

    • Re: Computer and User Certificates Issues
      ... Enrollment of User Certificates using the custom v2 User Certificate Template ... I can NOT request the custom v2 Computer Cert nor the included v1 no ... Concerning permissions, these are the exact permissions I am using now: ...
      (microsoft.public.security)
    • Re: Cannot request computer certificate.
      ... request a computer certificate for about 9 months. ... and verify that you can get a computer/server certificate from it. ... List of NetBt transports currently bound to the Redir ... DNS Host Name: srvr3.domain.com ...
      (microsoft.public.windows.server.security)
    • RE: SIMple SSL question ??
      ... OK - i would also delete a cert request file lying around. ... But a certificate is a pub key + extra info. ... That said - if someone compromises the server he will also find a way to retrieve the private key. ... traffic between the initial web server and the client. ...
      (microsoft.public.dotnet.security)
    • Re: how can we restrict what certificate WSE will use?
      ... the valid x509 certificate which is used to identify him'. ... X509SecurityTokenManager to verify the request is from a trusted client. ... the problem is that he can not passed the authentication (suppose we ... > decrypte and signature validation process. ...
      (microsoft.public.dotnet.framework.webservices.enhancements)
    • Re: Web Certificate Enrollment security problem
      ... Enrollment works only with the NetBIOS Name and not with the FQDN. ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ... access auditing and logging "issue and manage certificate requests" on ... Have seen that there is a component "Certsrv Request" when launching ...
      (microsoft.public.security)