Click here to get back home

PKI: Issue Computer Certificate

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
PKI: Issue Computer Certificate Patrik Nagel 09-19-2006
Get Chitika Premium
Posted by Patrik Nagel on September 19, 2006, 11:27 am
Please log in for more thread options
I try to issue a "RAS and IAS Server" certificate to a domain member
server (2003 SP1). I did make a copy of the original "RAS and IAS
Server" certificate template and changed only the security settings so
that the "RAS ans IAS Server" group has Read, Enroll and Autoenroll
permissions. The IAS Server is a member of the mentioned group.
Then, I've added (add - certificate template to issue) the template to
the issuing ca. But the copied template doesn't appear, when I open the
Web Enrollment Page ("create an submit request to this ca") on the IAS
Server (domain member). I also tried to request the IAS certificate by
using the Certificate Request Wizard (http://tinyurl.com/gco3x) on the
IAS Server.
The Enterprise Root CA is installed on W2003 R2 Enterprise Server. I can
issue user certificates (smartcard logon certs, enrollment agent for
user) without any problems.

TIA
Patrik

Posted by Brian Komar [MVP] on September 19, 2006, 5:15 pm
Please log in for more thread options
patrik.nagelREMOVE@THISsep.ch says...
> I try to issue a "RAS and IAS Server" certificate to a domain member
> server (2003 SP1). I did make a copy of the original "RAS and IAS
> Server" certificate template and changed only the security settings so
> that the "RAS ans IAS Server" group has Read, Enroll and Autoenroll
> permissions. The IAS Server is a member of the mentioned group.
> Then, I've added (add - certificate template to issue) the template to
> the issuing ca. But the copied template doesn't appear, when I open the
> Web Enrollment Page ("create an submit request to this ca") on the IAS
> Server (domain member). I also tried to request the IAS certificate by
> using the Certificate Request Wizard (http://tinyurl.com/gco3x) on the
> IAS Server.
> The Enterprise Root CA is installed on W2003 R2 Enterprise Server. I can
> issue user certificates (smartcard logon certs, enrollment agent for
> user) without any problems.
>
> TIA
> Patrik
>
You cannot request this certificate through the web enrollment page, as
it is being executed in your security context, not the server's security
context. The only computer certs that you can request through the Web
pages are those that you supply the subject of the cert in the request
or through pasting a CSR into the Web pages.

The certificate request wizard will work though. Did you meet the
minimum requirements:
1) Log on as a member of local Administrators.
2) Launch an empty MMC
3) Load the Certificates console focused on the Local Machine

If you just ran certmgr.msc you again are running as your local account,
not the local machine (which requires local admin access), and the
template will not be available.

Brian

Posted by Patrik Nagel on September 20, 2006, 2:58 am
Please log in for more thread options
Hello Brian

Brian Komar [MVP] wrote:
[snip]
> The certificate request wizard will work though. Did you meet the
> minimum requirements:
> 1) Log on as a member of local Administrators.
> 2) Launch an empty MMC
> 3) Load the Certificates console focused on the Local Machine

Yes, I meet all of these requirements. I just tried it again. The only
template which is available, is the "computer" type. I don't know what
else could be wrong. Do you have another idea?

For test purposes, I've also tried a different computer, which is also a
member or the "ras and ias server" group, to request the template.
Unfortunately with the same result as described above.

Thanks for your assistance
Patrik

Posted by Patrik Nagel on September 20, 2006, 3:59 am
Please log in for more thread options
Brian, it seems that the CSP in the template is the problem. In addition
to the "Microsoft RSA SChannel Cryptographic Provider", I've selected
the "Microsoft Base Cryptographic Provider 1.0" (as a test). This change
makes the Template available on the IAS-Server by using the MMC!
How can I add the Microsoft RSA SChannel Cryptographic Provider" to the
server?

Thanks again
Patrik

Posted by Patrik Nagel on September 20, 2006, 5:22 am
Please log in for more thread options
Patrik Nagel wrote:
> Brian, it seems that the CSP in the template is the problem. In addition
> to the "Microsoft RSA SChannel Cryptographic Provider", I've selected
> the "Microsoft Base Cryptographic Provider 1.0" (as a test). This change
> makes the Template available on the IAS-Server by using the MMC!

Sorry for this false statement. In addition to the CSP, I've also added
the global Group "Domain Computers" to the ACL with read and enroll
permissions. It seems that this change made the difference and not the
CSP. I can now install the certificate on the IAS-server with the "RSA
SChannel CSP".
I don't know why it didn't work with the "RAS and IAS Servers" group
(local domain scope). I added the computer-account to this group, but
that doesn't seem to work.

anyway, it works now!
Patrik

Similar ThreadsPosted
How to re-issue root CA certificate February 5, 2007, 8:50 pm
Issue certificate with notBefore in future July 5, 2005, 10:32 am
certificate server - design issue March 1, 2007, 9:49 pm
Certificate chain issue with Ent Sub Ca & stand alone Root CA April 27, 2006, 5:24 pm
Cannot request computer certificate. January 6, 2006, 1:00 pm
Custom COMPUTER certificate templates July 21, 2005, 1:57 pm
Help issuing computer certificate template not available? March 7, 2006, 4:32 pm
922706 Update and certificate for computer July 17, 2008, 8:51 am
2nd try: 922706 Update and certificate for computer July 22, 2008, 5:16 am
RPC Server Unavailable When Requesting Computer Certificate September 16, 2005, 12:07 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap