Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: Certificate Server help needed

Reply
Thread Tools Display Modes

Re: Certificate Server help needed

 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      08-26-2009
Hello Glenn,

I will crosspost this to:
microsoft.public.windows.server.security

Also think about using this forum:
http://social.technet.microsoft.com/...curity/threads

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I'm going through a process on a non-windows server, but one that is
> part of the domain, to get a certificate from our domain's certificate
> server.
>
> It doesn't prompt you for the FQDN, OU, location, etc., instead it has
> you enter the "LDAP entries required by your CA" in a field the
> software calls "Distinguished Name".
>
> It gives an example of
> cn=myaeserver.example.com,ou=myOrganizationalUnit, o=examplecorp,L=Spri
> ngfield,ST=Illinois,C=US
>
> I've tried, a few times, changing that line to my information, going
> through the request a certificate, import it, etc., but instead of it
> showing up as being used to the FQDN, it shows up as being issued to
> me (personally, my last name, first name shows up). I don't even
> include that in the Distinguished Name field, so it must pull it from
> my login.
>
> How can I request a certificate in this format so it will issue it to
> my FQDN?
>
> Thanks in advance,
> Glen



 
Reply With Quote
 
 
 
 
Martin Rublik
Guest
Posts: n/a

 
      08-26-2009

>> I'm going through a process on a non-windows server, but one that is
>> part of the domain, to get a certificate from our domain's certificate
>> server.
>>
>> It doesn't prompt you for the FQDN, OU, location, etc., instead it has
>> you enter the "LDAP entries required by your CA" in a field the
>> software calls "Distinguished Name".
>>
>> It gives an example of
>> cn=myaeserver.example.com,ou=myOrganizationalUnit, o=examplecorp,L=Spri
>> ngfield,ST=Illinois,C=US
>>
>> I've tried, a few times, changing that line to my information, going
>> through the request a certificate, import it, etc., but instead of it
>> showing up as being used to the FQDN, it shows up as being issued to
>> me (personally, my last name, first name shows up). I don't even
>> include that in the Distinguished Name field, so it must pull it from
>> my login.
>>
>> How can I request a certificate in this format so it will issue it to
>> my FQDN?
>>
>> Thanks in advance,
>> Glenn

>
>


Hi,

can you be more specific on how you are requesting a certificate. Please include
at least these information.

1. How is the request generated (what application is used).
2. How is the request submitted to CA.
3. Do you use enterprise or standalone certificate server.
4. If you use enterprise certificate server, what kind of certificate template
are you enrolling.

Regards

Martin

--
Replace nospam with google's mail for e-mail communication
 
Reply With Quote
 
Glenn
Guest
Posts: n/a

 
      08-26-2009
To answer your questions,

1) I am generating the request using Avaya Application Enablement Services.
It generates the code at the end (---Begin Certificate----, etc.) which I
copy to the clipboard.
2) I then go to http://myserver/certsrv and click "Request a certificate",
then "advanced certificate request", then "Submit a certificate request by
using a base-64..." I then paste the clipboard into the saved request area
and click submit. I download it as base 64
3) Standalone certificate server (as far as I can tell).

Thanks.


"Martin Rublik" <> wrote in message
news:%....
>>> I'm going through a process on a non-windows server, but one that is
>>> part of the domain, to get a certificate from our domain's certificate
>>> server.
>>>
>>> It doesn't prompt you for the FQDN, OU, location, etc., instead it has
>>> you enter the "LDAP entries required by your CA" in a field the
>>> software calls "Distinguished Name".
>>>
>>> It gives an example of
>>> cn=myaeserver.example.com,ou=myOrganizationalUnit, o=examplecorp,L=Spri
>>> ngfield,ST=Illinois,C=US
>>>
>>> I've tried, a few times, changing that line to my information, going
>>> through the request a certificate, import it, etc., but instead of it
>>> showing up as being used to the FQDN, it shows up as being issued to
>>> me (personally, my last name, first name shows up). I don't even
>>> include that in the Distinguished Name field, so it must pull it from
>>> my login.
>>>
>>> How can I request a certificate in this format so it will issue it to
>>> my FQDN?
>>>
>>> Thanks in advance,
>>> Glenn

>>
>>

>
> Hi,
>
> can you be more specific on how you are requesting a certificate. Please
> include
> at least these information.
>
> 1. How is the request generated (what application is used).
> 2. How is the request submitted to CA.
> 3. Do you use enterprise or standalone certificate server.
> 4. If you use enterprise certificate server, what kind of certificate
> template
> are you enrolling.
>
> Regards
>
> Martin
>
> --
> Replace nospam with google's mail for e-mail communication



 
Reply With Quote
 
Glenn
Guest
Posts: n/a

 
      08-26-2009
Problem solved. I needed to use the web server template.


"Glenn" <> wrote in message
news:...
> To answer your questions,
>
> 1) I am generating the request using Avaya Application Enablement
> Services. It generates the code at the end (---Begin Certificate----,
> etc.) which I copy to the clipboard.
> 2) I then go to http://myserver/certsrv and click "Request a
> certificate", then "advanced certificate request", then "Submit a
> certificate request by using a base-64..." I then paste the clipboard into
> the saved request area and click submit. I download it as base 64
> 3) Standalone certificate server (as far as I can tell).
>
> Thanks.
>
>
> "Martin Rublik" <> wrote in message
> news:%....
>>>> I'm going through a process on a non-windows server, but one that is
>>>> part of the domain, to get a certificate from our domain's certificate
>>>> server.
>>>>
>>>> It doesn't prompt you for the FQDN, OU, location, etc., instead it has
>>>> you enter the "LDAP entries required by your CA" in a field the
>>>> software calls "Distinguished Name".
>>>>
>>>> It gives an example of
>>>> cn=myaeserver.example.com,ou=myOrganizationalUnit, o=examplecorp,L=Spri
>>>> ngfield,ST=Illinois,C=US
>>>>
>>>> I've tried, a few times, changing that line to my information, going
>>>> through the request a certificate, import it, etc., but instead of it
>>>> showing up as being used to the FQDN, it shows up as being issued to
>>>> me (personally, my last name, first name shows up). I don't even
>>>> include that in the Distinguished Name field, so it must pull it from
>>>> my login.
>>>>
>>>> How can I request a certificate in this format so it will issue it to
>>>> my FQDN?
>>>>
>>>> Thanks in advance,
>>>> Glenn
>>>
>>>

>>
>> Hi,
>>
>> can you be more specific on how you are requesting a certificate. Please
>> include
>> at least these information.
>>
>> 1. How is the request generated (what application is used).
>> 2. How is the request submitted to CA.
>> 3. Do you use enterprise or standalone certificate server.
>> 4. If you use enterprise certificate server, what kind of certificate
>> template
>> are you enrolling.
>>
>> Regards
>>
>> Martin
>>
>> --
>> Replace nospam with google's mail for e-mail communication

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Certificate Server help needed Glenn Windows Server 4 08-26-2009 03:37 PM
SBS - connecting to mobile device help with certificate needed GMan Windows Small Business Server 5 11-19-2007 03:39 PM
Invalid security certificate information not available when needed Tepee Internet Explorer 1 05-12-2006 03:38 AM
Help needed with Web Server Certificate pls Nick Windows Small Business Server 1 07-28-2005 08:26 AM
Certificate server: Automatic certificate enrollment for local system failed Kasper Windows Server 0 03-22-2005 11:10 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59