Re: Certificate on Juniper's Steel Belted Radius Server



In article <Ok9qvMhVHHA.4668@xxxxxxxxxxxxxxxxxxxx>,
gel114@xxxxxxxxxxxxxxxxx says...
I have a CA on my Win2003 set up and need to generate a certificate for my
Steel Belted Radius server. What template version do I use for the radius
server. using the http://CAServer/certsrv I get 6 options for certificate
templates.
1. Administrator
2. Basic EFS
3. EFS Recovery Agent
4. User
5. Subordinate Certificate Authority
6. Web Server
I've tried #3 and #4, but get "wrong certificate type" error with the radius
server. I need to export the private keys and strong private key protection.
Any ideas of what I'm doing wrong.
Thank you



You cannot request certificates from the web pages, as
they are in the security context of the user, not the
machine. You would need to create a custom v2
certificate template that allows the user to provide the
subject name in the request.
You really need to read the documentation for SBR, but
you can probably duplicate the RAS and IAS Server
certificate template, but change the subject to provide
in request.
You can then set the permissions to the user account
requesting the certificate.

Brian
P.S. The CA must be running as an enterprise CA running
on Windows Server 2003, Enterprise Edition.
.



Relevant Pages

  • Re: Cannot request certificate on client computer
    ... re-connect both computer and user account on the server. ... PC and the certificate request now works. ... (I'd check both the server and the client PC). ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot request certificate on client computer
    ... re-connect both computer and user account on the server. ... one PC and the certificate request now works. ... (I'd check both the server and the client PC). ...
    (microsoft.public.windows.server.sbs)
  • RE: Wireless connection problem from XP Pro SP2 to SBS 2003
    ... the screen I'm seeing under advanced request is a little different than what ... In Type of Certificate needed, click Server Authentication Certificate. ...
    (microsoft.public.windows.server.sbs)
  • Re: Generate SSL certificate request from ISA server
    ... when you receive the certificate from the authority, install it on the ISA ... Server instead of the web server. ... > request to send to them, which doesn't appear to be possible directly from ...
    (microsoft.public.isa.configuration)
  • Re: Cannot request computer certificate.
    ... I did a cerutil -ping from the server again and now it is working: ... >>whole problem since you can not request a certificate while logged onto ... >> I would verify that the certificate services service is running and set ... >>> The redir is bound to 1 NetBt transport. ...
    (microsoft.public.windows.server.security)