Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

2008 CA issues.

Status
Not open for further replies.

wiimike

IS-IT--Management
Mar 30, 2007
145
US
Hi all,

Certificates are new to me, but I've been working with them for the past few weeks. My goal is to get apache on server 2008 working with ssl, using a certificate that fits. We have a 2008CA in the environment. I need a .crt output with a decent length valid period. I believe I can change the .cer to a .crt with openssl conversions. My problem is NOT getting it to work with apache, my problem is getting the correct certificate output.

I can create a csr from my apache server using openssl. I can then go into 2008rootca/certsrv, choose request, my only options are then user or advanced, Create and submit a request to this CA, this ONLY ALLOWS ME TO SELECT "basic efs" and "user". I'm sure there's something to be done to be able to use the others, but I do not see what. I've googled a bunch but only come across things telling me to duplicate templates via a process that no longer works in 2008 (right click, duplicate).

My other options is to "Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.", in which case it keeps issuing certificates to my username.

In neither case do I see an option to change the length of the certificate time.

Any help you can give is appreciated, and if not thanks so much for at least reading through in an effort to help.
 
what templates does your CA have installed??

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Agreed...it's down to templates. It sounds like you only have templates for EFS and user identification enabled, or you only have rights to request certificates of those types. Are you the CA admin or is there someone else who handles that?

________________________________________
CompTIA A+, Network+, Server+, Security+
MCTS:Windows 7
MCSE:Security 2003
MCITP:Server Administrator
MCITP:Enterprise Administrator
MCITP:Virtualization Administrator 2008 R2
Certified Quest vWorkspace Administrator
 
I am a domain admin. I'm not sure if that gives me the required rights. Is there a role past that I need to hold?

The Templates I have installed (by this I mean if I open the certificate authority snap in, under certificate templates, I see these) I have
SCCM_AMT_Web_Server
SCCM_AMT_Provisioning
Directory Email Replication
Domain Controller Authentication
EFS Recovery Agent
Basic EFS
Domain Controller
Web Server
Computer
User
Subordinate Certification Authority
Administrator
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top