Certificate Web Enrollment (Server 2003 and Vista)

Certificate Web Enrollment (Server 2003 and Vista)

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Certificate Web Enrollment (Server 2003 and Vista) Tim D 11-14-2008
Posted by =?Utf-8?B?VGltIEQ=?= on November 14, 2008, 12:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Problem:
After installing the Certificate Services Web enrollment pages update
KB922706 on Windows Server 2003 the “install this CA certificate” link
generates an invalid security certificate for Windows Vista clients.

More:
For Vista clients, the screen to install the digital certificate states that
“the Certificate you requested was issued to you” after the certificate is
issued and then provides a link to “Install this certificate”. It then lists
“This CA is not trusted. To trust certificates issued from this certification
authority, install this CA certificate.”

After selecting “install this CA certificate” a file named certnew.cer is
generated. Saving or directly opening both result in an error message being
displayed with the title “invalid public key security object file” and the
message “this file is invalid for use as the following: Security
Certificate”.

Steps that I’ve already taken:
The web enrollment URL was added to the trusted sites in IE7 on Vista.
I’ve tried “Run as administrator” on IE7 to make the certificate request.
SP2 has been applied on the Windows Server 2003 CA server.
The ActiveX security settings look OK.

Note:
The web enrollment continues to work for Windows XP clients.

My Current Workaround:
Exporting the Root Certificate from an XP computer and installing it on the
Vista client enabled the web enrollment process to work. Using an advanced
request and selecting a 2048 key size created a certificate that could be
installed.

Server:
Microsoft Windows Server 2003
Standard Edition
Service Pack 2

Client:
Windows Vista Enterprise
Service Pack 1

Question:
How can I get the web enrollment process to install the Root Certificate
automatically using Vista Clients without requiring the workaround?


Similar ThreadsPosted
Certificate Enrollment on behalf of others on a W2003 Standard Server June 18, 2008, 8:02 am
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:33 pm
Certificate Error on 2003 server November 14, 2005, 2:23 pm
Certificate enroll with Windows Server 2003? December 12, 2005, 9:46 pm
Certificate enroll with Windows Server 2003? December 12, 2005, 10:36 pm
Certificate problem with Windows Server 2003 May 22, 2006, 12:25 pm
Using Server 2003 to sign Sonicwall VPN certificate March 27, 2007, 3:52 am
Windows 2000 Certificate server---->2003 August 26, 2008, 3:52 pm
Using SSL Certificate for TSAC on NLB Windows 2003 Terminal Server March 28, 2006, 11:42 am
Certificate Services features vs Windows 2003 server editions May 24, 2006, 3:17 pm

The site map in XML format XML site map

Contact Us | Privacy Policy