Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: certificate server

Reply
Thread Tools Display Modes

Re: certificate server

 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-18-2009
Hello David,

I will crosspost this to:
microsoft.public.windows.server.security

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi,
>
> We have a windows 2003 active directory, with an exchange 2003
> organization. We had a certificate server which was also a DC. It had
> an unrecoverable error some months ago. We could have domain working
> as we have more DCs, but we are still using a certificate for OWA and
> RPC over https created by the certificate server.
>
> I have some problems with public folder replication, because of the
> lack of this certificate erver. We also have some problems to navigate
> through the Exchange System administration console, concretely the
> public folders.
>
> I also have some problems in the domain controllers, Event viewer
> says: "Automatic certificate inscriptions failed for Local System,
> cannot inscribe a DC certificate. RPC server is not available" (Sorry,
> this is a myself translation from Spanish)
>
> Now I've noticed that the certificate will expire in a few months.
>
> I would like to change this certificate, and make it work in the
> domain and the Exchange System, so I can solve this problems.
>
> Which is the best way? Should I install a new certificate server? How
> I can I solve those replication problems? Is there any thing I should
> keep in mind before trying a new certificate server?
>
> Thank you very much for your answers.
>
> Kind Regards.
>
> David Fernández.
>



 
Reply With Quote
 
 
 
 
David Fernandez
Guest
Posts: n/a

 
      04-14-2009
Hello,

I have a new question.

If I remove my CA from the domain, and create a new one, will the
certificate that I created with the old one work until I create a new
certificate and install it on the server?

Thank you for your answers.

Kind regards



"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> escribió en el mensaje
news: .com...
> Hello David,
>
> I will crosspost this to:
> microsoft.public.windows.server.security
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> Hi,
>>
>> We have a windows 2003 active directory, with an exchange 2003
>> organization. We had a certificate server which was also a DC. It had
>> an unrecoverable error some months ago. We could have domain working
>> as we have more DCs, but we are still using a certificate for OWA and
>> RPC over https created by the certificate server.
>>
>> I have some problems with public folder replication, because of the
>> lack of this certificate erver. We also have some problems to navigate
>> through the Exchange System administration console, concretely the
>> public folders.
>>
>> I also have some problems in the domain controllers, Event viewer
>> says: "Automatic certificate inscriptions failed for Local System,
>> cannot inscribe a DC certificate. RPC server is not available" (Sorry,
>> this is a myself translation from Spanish)
>>
>> Now I've noticed that the certificate will expire in a few months.
>>
>> I would like to change this certificate, and make it work in the
>> domain and the Exchange System, so I can solve this problems.
>>
>> Which is the best way? Should I install a new certificate server? How
>> I can I solve those replication problems? Is there any thing I should
>> keep in mind before trying a new certificate server?
>>
>> Thank you very much for your answers.
>>
>> Kind Regards.
>>
>> David Fernández.
>>

>
>



 
Reply With Quote
 
Brian Komar \(MVP\)
Guest
Posts: n/a

 
      04-15-2009
No. You need to maintain certificate revocation lists for all previously
issued certificatese until they are replaced.,
This would have to be maintained until the last previously issued
certificate expires.
Brian

"David Fernandez" <> wrote in message
news:%...
> Hello,
>
> I have a new question.
>
> If I remove my CA from the domain, and create a new one, will the
> certificate that I created with the old one work until I create a new
> certificate and install it on the server?
>
> Thank you for your answers.
>
> Kind regards
>
>
>
> "Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> escribió en el mensaje
> news: .com...
>> Hello David,
>>
>> I will crosspost this to:
>> microsoft.public.windows.server.security
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>
>>> Hi,
>>>
>>> We have a windows 2003 active directory, with an exchange 2003
>>> organization. We had a certificate server which was also a DC. It had
>>> an unrecoverable error some months ago. We could have domain working
>>> as we have more DCs, but we are still using a certificate for OWA and
>>> RPC over https created by the certificate server.
>>>
>>> I have some problems with public folder replication, because of the
>>> lack of this certificate erver. We also have some problems to navigate
>>> through the Exchange System administration console, concretely the
>>> public folders.
>>>
>>> I also have some problems in the domain controllers, Event viewer
>>> says: "Automatic certificate inscriptions failed for Local System,
>>> cannot inscribe a DC certificate. RPC server is not available" (Sorry,
>>> this is a myself translation from Spanish)
>>>
>>> Now I've noticed that the certificate will expire in a few months.
>>>
>>> I would like to change this certificate, and make it work in the
>>> domain and the Exchange System, so I can solve this problems.
>>>
>>> Which is the best way? Should I install a new certificate server? How
>>> I can I solve those replication problems? Is there any thing I should
>>> keep in mind before trying a new certificate server?
>>>
>>> Thank you very much for your answers.
>>>
>>> Kind Regards.
>>>
>>> David Fernández.
>>>

>>
>>

>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
sbs 2k3 - certificate authority web server template - not being able to issue a certificate Pedro M. Leite Windows Small Business Server 3 05-14-2007 05:24 PM
Re: Move Certificate Authority to new server w/o renaming old server? Jorge de Almeida Pinto [MVP - DS] Active Directory 0 12-21-2006 01:31 PM
Re: Problem when requesting a certificate to IIS server (certificate web enrollment) Steven L Umbach Server Security 2 10-14-2005 01:11 PM
Re: Certificate Server won't start on Windows Server 2003 Gopi Active Directory 0 10-08-2005 08:43 AM
Certificate server: Automatic certificate enrollment for local system failed Kasper Windows Server 0 03-22-2005 11:10 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59