Click here to get back home

Offline CA Root certificate invisble in AD

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Offline CA Root certificate invisble in AD BENHAMOU Stéph 03-21-2007
Posted by BENHAMOU Stéph on March 21, 2007, 3:48 pm
Please log in for more thread options
Hi,

I'm implementing a pki to secure our WLAN network. I followed the guidelines
found on the MS Solution "Securing Wireless LANs with Certificate Services".

I installed a Win 2003 SP1 Std Server for Offline CA Root, exported the
certificate and CRL and then imported them in AD through the certutil utility
(certutil -v -f -dsPublish -dc ...)

When I check on a member server if the certificate is published (certutil
-viewstore -enterprise Root), I got nothing. But when I go to the
Configuration, Service, Public Key Services, Certification Authorities, the
CN name of my Root CA certificate is there, with a certificationAuthority
class !

Can someone tell me why the Root CA certificate is not visible but seems to
be installed ? How could I make him visible to verify that everything is fine
?

Thanks in advance.

Stéphane

Posted by Brian Komar [MVP] on March 21, 2007, 5:07 pm
Please log in for more thread options
In article <A4CFAEF5-D6A2-4934-AABC-D9DB63D5FF66
@microsoft.com>,=20
BENHAMOUStphane@discussions.microsoft.com says...
> Hi,=20
>=20
> I'm implementing a pki to secure our WLAN network. I followed the guideli=
nes=20
> found on the MS Solution "Securing Wireless LANs with Certificate Service=
s".=20
>=20
> I installed a Win 2003 SP1 Std Server for Offline CA Root, exported the=
=20
> certificate and CRL and then imported them in AD through the certutil uti=
lity=20
> (certutil -v -f -dsPublish -dc ...)
>=20
> When I check on a member server if the certificate is published (certutil=
=20
> -viewstore -enterprise Root), I got nothing. But when I go to the=20
> Configuration, Service, Public Key Services, Certification Authorities, t=
he=20
> CN name of my Root CA certificate is there, with a certificationAuthority=
=20
> class !
>=20
> Can someone tell me why the Root CA certificate is not visible but seems =
to=20
> be installed ? How could I make him visible to verify that everything is =
fine=20
> ?
>=20
> Thanks in advance.
>=20
> St=C3=A9phane
>=20
It may just be a case of patience. I just checked a few=20
of my environments , and in all cases , I see the=20
certificate in both the etnerprise root, and in the=20
certificate manager.

THe best way to check if the publication is successful=20
is to use the PKI Health Tool (pkiview.msc). Ensure that=20
the root certificate is on both the Certification=20
Authorities and AIA tab.

Also, you cut off the important command <G>. Did you=20
type:
certutil -v -f -dsPublish <RootCertName.cer> RootCA


Brian

Posted by BENHAMOU Stéph on March 22, 2007, 8:02 am
Please log in for more thread options


"Brian Komar [MVP]" wrote:

> In article <A4CFAEF5-D6A2-4934-AABC-D9DB63D5FF66
> @microsoft.com>,
> BENHAMOUStphane@discussions.microsoft.com says...
> > Hi,
> >
> > I'm implementing a pki to secure our WLAN network. I followed the guidelines
> > found on the MS Solution "Securing Wireless LANs with Certificate Services".
> >
> > I installed a Win 2003 SP1 Std Server for Offline CA Root, exported the
> > certificate and CRL and then imported them in AD through the certutil
utility
> > (certutil -v -f -dsPublish -dc ...)
> >
> > When I check on a member server if the certificate is published (certutil
> > -viewstore -enterprise Root), I got nothing. But when I go to the
> > Configuration, Service, Public Key Services, Certification Authorities, the
> > CN name of my Root CA certificate is there, with a certificationAuthority
> > class !
> >
> > Can someone tell me why the Root CA certificate is not visible but seems to
> > be installed ? How could I make him visible to verify that everything is
fine
> > ?
> >
> > Thanks in advance.
> >
> > Stéphane
> >
> It may just be a case of patience. I just checked a few
> of my environments , and in all cases , I see the
> certificate in both the etnerprise root, and in the
> certificate manager.
>
> THe best way to check if the publication is successful
> is to use the PKI Health Tool (pkiview.msc). Ensure that
> the root certificate is on both the Certification
> Authorities and AIA tab.
>
> Also, you cut off the important command <G>. Did you
> type:
> certutil -v -f -dsPublish <RootCertName.cer> RootCA
>
>
> Brian
>

of course, I type the following command : certutil -v -f -dsPublish -dc MYDC
"A:\CACERT\RootCertName.crt" RootCA

When I replay this command, I get a "Certificate already in store" response,
but can't still view it

Similar ThreadsPosted
Offline Root CA October 6, 2008, 2:56 pm
Offline Root CA and CDP/AIA paths August 29, 2005, 8:26 am
Offline Root CA CDP Expiring April 26, 2006, 2:46 am
Publish Offline Root CRL June 3, 2008, 12:07 pm
Publishing offline root in AD and AIA and capolicy.inf July 12, 2005, 11:26 pm
PKI - Single Offline Root for Multiple Forest March 24, 2008, 9:02 pm
Offline certificate creation fails on Windows 2003 enterprise CA without IIS March 27, 2006, 7:41 pm
Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ? March 26, 2008, 6:20 am
Root Certificate Authority October 22, 2006, 6:35 am
How to re-issue root CA certificate February 5, 2007, 8:50 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap