Click here to get back home

Not certified for Certificate Signing

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Not certified for Certificate Signing <-> 10-12-2005
Posted by <-> on October 12, 2005, 7:48 pm
Please log in for more thread options
HELP!!!

We are trying to convert a certificate from .CER format to OpenSSL format,
for Active Directory domain controllers so that Siteminder can use them. In
Windows everything looks fine (the certificate chain up through the
intermediate CA to the root CA is fine) but when we try to verify the
certificates generated via autoenrollment for the DC's we get this message:

"Not certified for Certificate Signing"

Here's the really strange part: as an experiment I exported additional
copies of rht .CER versions of the two certificates which were successfully
converted to OpenSSL back in December of last year. We have to use Netscape
4.x in order to do this. They are obviously working because Siteminder is
successfully using them right now. But even THEY gave the same "Not
certified for Certificate Signing" when I took them through the process
again. I'm thinking there must be something in the process I'm not doing
right. I know they're not really for signing other certificates, they're
just for client/server authentication and for LDAP over SSL, but I don't
know what I need to do to get them verified.

Any suggestions appreciated




Posted by S. Pidgorny on October 13, 2005, 9:09 pm
Please log in for more thread options
The message does make sense: the DC certificate doesn't have the Certificate
Signing key usage attribute. Only CA certificates have that attribute. Why
would SiteMinder require using a CA certificate?

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> HELP!!!
>
> We are trying to convert a certificate from .CER format to OpenSSL format,
> for Active Directory domain controllers so that Siteminder can use them.
In
> Windows everything looks fine (the certificate chain up through the
> intermediate CA to the root CA is fine) but when we try to verify the
> certificates generated via autoenrollment for the DC's we get this
message:
>
> "Not certified for Certificate Signing"
>
> Here's the really strange part: as an experiment I exported additional
> copies of rht .CER versions of the two certificates which were
successfully
> converted to OpenSSL back in December of last year. We have to use
Netscape
> 4.x in order to do this. They are obviously working because Siteminder is
> successfully using them right now. But even THEY gave the same "Not
> certified for Certificate Signing" when I took them through the process
> again. I'm thinking there must be something in the process I'm not doing
> right. I know they're not really for signing other certificates, they're
> just for client/server authentication and for LDAP over SSL, but I don't
> know what I need to do to get them verified.
>
> Any suggestions appreciated
>
>




Similar ThreadsPosted
Signing an OpenSSL CSR with Microsoft Certificate Authority July 24, 2005, 10:33 am
PKI: CA Signing Key Expiry and CRL Publication July 8, 2005, 7:41 am
Permanently disable SMB signing February 22, 2006, 8:09 pm
SMB signing on member server November 26, 2007, 12:40 pm
Several questions on code signing / smartcards / Win CA August 25, 2005, 4:24 am
Code Signing Cert not trusted? October 19, 2007, 1:33 pm
Group Policy Options for Signing and Encryption November 30, 2005, 2:28 am
Expired Code Signing Cert with VBScript September 12, 2006, 9:17 am
Requesting Code signing cert from cert services November 4, 2005, 12:11 pm
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:31 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap