Click here to get back home

Online request of a certificate with CA in another domain

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Online request of a certificate with CA in another domain Mike Celone 01-26-2007
Posted by Mike Celone on January 26, 2007, 11:39 am
Please log in for more thread options
I have installed an Enterprise Root CA in the root of our AD Forest. I have
been able to request a certificate (user certificate template) using an
account in one of the child domains successfully using the CertSrv webpages.

I am now trying to submit an online certificate request through IIS on a
Windows 2003 machine and have not been successful. The option is available
to submit it online and it can see the CA (it shows up in the drop down
menu) but when the wizard finishes I have no certificate installed. I have
verified that the user account I am using has rights to read and enroll a
web server certificate template by going to the Certsrv webpages and web
server shows up in the list of templates I can request. Are there some
other permissions I need to set to request online certificates?

Mike



Posted by Paul Adare on January 26, 2007, 12:08 pm
Please log in for more thread options
microsoft.public.windows.server.security news group, Mike Celone

> I am now trying to submit an online certificate request through IIS on a
> Windows 2003 machine and have not been successful. The option is available
> to submit it online and it can see the CA (it shows up in the drop down
> menu) but when the wizard finishes I have no certificate installed. I have
> verified that the user account I am using has rights to read and enroll a
> web server certificate template by going to the Certsrv webpages and web
> server shows up in the list of templates I can request. Are there some
> other permissions I need to set to request online certificates?

Do you have the default version 1 Web Server certificate
template published or are you using a custom version 2 template?
If the latter it won't work as the IIS wizard is hard coded for
the version 1 template and can't be changed.
Also, does the computer itself have permissions on the template
(authenticated users is enough)? When using the IIS wizard it
doesn't matter which user account you're using, the request is
submitted in the security context of the computer account.

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld


Posted by Mike Celone on January 26, 2007, 12:39 pm
Please log in for more thread options
I am using the Version 1 certificate I believe. From what I have read you
need Windows 2003 Enterprise to use Version 2 certificates and the CA is
Windows 2003 Standard. However I don't believe that Authenticated Users is
enough since I had to add our the Domain Users groups from our child domains
to the Certificate Templates in order to allow the child domain users to see
the certificates. The Domain Computers group from the child domain does not
have permissions to the Web Server certificate. I'll attempt to add that
now and see how it works.


Mike

> microsoft.public.windows.server.security news group, Mike Celone
>
>> I am now trying to submit an online certificate request through IIS on a
>> Windows 2003 machine and have not been successful. The option is
>> available
>> to submit it online and it can see the CA (it shows up in the drop down
>> menu) but when the wizard finishes I have no certificate installed. I
>> have
>> verified that the user account I am using has rights to read and enroll a
>> web server certificate template by going to the Certsrv webpages and web
>> server shows up in the list of templates I can request. Are there some
>> other permissions I need to set to request online certificates?
>
> Do you have the default version 1 Web Server certificate
> template published or are you using a custom version 2 template?
> If the latter it won't work as the IIS wizard is hard coded for
> the version 1 template and can't be changed.
> Also, does the computer itself have permissions on the template
> (authenticated users is enough)? When using the IIS wizard it
> doesn't matter which user account you're using, the request is
> submitted in the security context of the computer account.
>
> --
> Paul Adare - MVP Virtual Machines
> Waiting for a bus is about as thrilling as fishing,
> with the similar tantalisation that something,
> sometime, somehow, will turn up. George Courtauld
>



Similar ThreadsPosted
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am
Create Certificate Request for Windows2003 certificate authority without using website March 22, 2006, 8:07 am
add UPN in certificate Request February 19, 2007, 7:21 am
Cannot request computer certificate. January 6, 2006, 1:00 pm
PKI Certificate request from another forest September 14, 2006, 4:28 pm
Specifying publication location in the certificate request October 8, 2005, 2:03 am
Certificate Services could not process request January 2, 2007, 9:31 pm
PKI difference between "Advanced Certificate Request" May 28, 2008, 10:38 am
Request certificate to a CA in Windows server 2003 January 26, 2007, 12:44 pm
automatic certificate request GPO VS Auto enroll February 19, 2008, 1:50 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap