Re: Offline CA Root certificate invisble in AD



In article <A4CFAEF5-D6A2-4934-AABC-D9DB63D5FF66
@microsoft.com>,
BENHAMOUStphane@xxxxxxxxxxxxxxxxxxxxxxxxx says...
Hi,

I'm implementing a pki to secure our WLAN network. I followed the guidelines
found on the MS Solution "Securing Wireless LANs with Certificate Services".

I installed a Win 2003 SP1 Std Server for Offline CA Root, exported the
certificate and CRL and then imported them in AD through the certutil utility
(certutil -v -f -dsPublish -dc ...)

When I check on a member server if the certificate is published (certutil
-viewstore -enterprise Root), I got nothing. But when I go to the
Configuration, Service, Public Key Services, Certification Authorities, the
CN name of my Root CA certificate is there, with a certificationAuthority
class !

Can someone tell me why the Root CA certificate is not visible but seems to
be installed ? How could I make him visible to verify that everything is fine
?

Thanks in advance.

Stéphane

It may just be a case of patience. I just checked a few
of my environments , and in all cases , I see the
certificate in both the etnerprise root, and in the
certificate manager.

THe best way to check if the publication is successful
is to use the PKI Health Tool (pkiview.msc). Ensure that
the root certificate is on both the Certification
Authorities and AIA tab.

Also, you cut off the important command <G>. Did you
type:
certutil -v -f -dsPublish <RootCertName.cer> RootCA


Brian
.



Relevant Pages

  • Re: Certificate chain issue with Ent Sub Ca & stand alone Root CA
    ... certificate and I get a "Cannot verify certificate chain. ... revocation because the revocation server was offline. ... the root ca? ... Online>>> Online Enterprise Subordinate CA ...
    (microsoft.public.windows.server.security)
  • Re: Newbie wants to learn about PKI Server 2003......
    ... 2003 PKI Certificate Security", and have been lurking here for a bit. ... We will implement a 2 tier heirarchy, with the Root CA being offline. ... All clients that attempt revocation checking will first attempt to retrieve the CRL from the ... level below a self-signed cert, so applications that are 3280 compliant would never check the ...
    (microsoft.public.windows.server.security)
  • Re: Is it possible??.... Defining Root Certificate KeyUsage
    ... For instance, the self signed certificate ... intermediate servers list every possible key usage defined within the PKI ... Component Verification, OEM Windows System Component Verification, Embedded ... Since the only use these root and intermediate keys are designed for is ...
    (microsoft.public.security)
  • Re: Is it possible??.... Defining Root Certificate KeyUsage
    ... For instance, the self signed certificate ... intermediate servers list every possible key usage defined within the PKI ... Component Verification, OEM Windows System Component Verification, Embedded ... Since the only use these root and intermediate keys are designed for is ...
    (microsoft.public.inetserver.iis.security)
  • Re: Is it possible??.... Defining Root Certificate KeyUsage
    ... For instance, the self signed certificate ... intermediate servers list every possible key usage defined within the PKI ... Component Verification, OEM Windows System Component Verification, Embedded ... Since the only use these root and intermediate keys are designed for is ...
    (microsoft.public.win2000.security)