Click here to get back home

PKI Certificate request from another forest

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
PKI Certificate request from another forest chriss3 [MVP] 09-14-2006
Posted by chriss3 [MVP] on September 14, 2006, 4:28 pm
Please log in for more thread options
Hello,
Is there anyway to issue certificates to an IIS webserver that belongs to
another Active Directory Forest than the Enterprise Root CA i'm trying to
issue the certificate from. I tried to prepare a certificate request, but
when i'm trying to import the request file i get an error message saying
that the request dosen't contain any certificate template. Note: I don't
have the IIS Web-Based enrollment installed since i want to avoid install
IIS on the CA Server since it also a DC.

Any suggestions on this issue?

Thanks
Christoffer


Posted by neo [mvp outlook] on September 14, 2006, 7:52 pm
Please log in for more thread options
Best guess based on googling... the certreq.exe tool. (e.g. on the IIS
webserver, create the request via IIS managment snapin and save to file.
Copy the *.req file to the CA and use the certreq tool to submit it.)

> Hello,
> Is there anyway to issue certificates to an IIS webserver that belongs to
> another Active Directory Forest than the Enterprise Root CA i'm trying to
> issue the certificate from. I tried to prepare a certificate request, but
> when i'm trying to import the request file i get an error message saying
> that the request dosen't contain any certificate template. Note: I don't
> have the IIS Web-Based enrollment installed since i want to avoid install
> IIS on the CA Server since it also a DC.
>
> Any suggestions on this issue?
>
> Thanks
> Christoffer



Posted by Brian Komar [MVP] on September 15, 2006, 7:27 am
Please log in for more thread options
> Best guess based on googling... the certreq.exe tool. (e.g. on the IIS
> webserver, create the request via IIS managment snapin and save to file.
> Copy the *.req file to the CA and use the certreq tool to submit it.)
>
> > Hello,
> > Is there anyway to issue certificates to an IIS webserver that belongs to
> > another Active Directory Forest than the Enterprise Root CA i'm trying to
> > issue the certificate from. I tried to prepare a certificate request, but
> > when i'm trying to import the request file i get an error message saying
> > that the request dosen't contain any certificate template. Note: I don't
> > have the IIS Web-Based enrollment installed since i want to avoid install
> > IIS on the CA Server since it also a DC.
> >
> > Any suggestions on this issue?
> >
> > Thanks
> > Christoffer
>
>
>
Also, reconsider cohosting a CA and DC. The WEB interface makes life a lot
easier> Also, most
companies run into trouble down the road when they co-host a CA and DC, as it
makes it very
difficult to decommision (you cannot demote the DC, nor move certificate
services to a
different computer).
Brian

Similar ThreadsPosted
Insufficient rights to edit all GPOs in local forest from account in trusted forest. August 15, 2006, 1:21 pm
Create Certificate Request for Windows2003 certificate authority without using website March 22, 2006, 8:07 am
add UPN in certificate Request February 19, 2007, 7:21 am
Cannot request computer certificate. January 6, 2006, 1:00 pm
Specifying publication location in the certificate request October 8, 2005, 2:03 am
Certificate Services could not process request January 2, 2007, 9:31 pm
Online request of a certificate with CA in another domain January 26, 2007, 11:39 am
PKI difference between "Advanced Certificate Request" May 28, 2008, 10:38 am
Request certificate to a CA in Windows server 2003 January 26, 2007, 12:44 pm
automatic certificate request GPO VS Auto enroll February 19, 2008, 1:50 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap