Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
Error: 0x00000046 - when requesting certificates
Error: 0x00000046  - when requesting certificates

Error: 0x00000046 - when requesting certificates

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Error: 0x00000046 - when requesting certificates DJH 12-03-2007
Posted by =?Utf-8?B?REpI?= on December 3, 2007, 9:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hey,

We have an internal PKI utilising an offlint root and policy server, and an
AD integrated enterprise issuing server. We've distributed our root
certificate via a GPO to all workstations/servers in AD.

We have a number of certifcate templates for SSL certs. We permission these
with Role groups to define who can request and modify the certs.

We have one problematic box, when requesting a certificate via
servername\certsrv we get a permission denied error:

"An error occurred while creating the certificate request. Please verify
that your CSP supports any settings you have made and that your input is
valid.         
Suggested cause:
You do not have write permission to save the file to the path        
Error: 0x00000046 - Permission Denied"

The request is for a generic SSL certificate so that a secure channel can be
used to communicate between 2 boxes. The certificate request never reaches
the enterprise issuing server (no record of failed request). The error
message indicates a permission issue, but the way we permission the templates
is such that you wont see the cert via the web interface if your not a member
of the group which can request this certificate type. The user requesting the
certificate is a member of builtin\administrators of the box requesting the
certificate.

Anyone have any suggestions?

Posted by =?Utf-8?B?REpI?= on December 4, 2007, 11:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Found it!

Permissions on the local certificate store were incorrect. for some reason
administrators only had read!

Local certificate store location:
C:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys

"DJH" wrote:

> Hey,
>
> We have an internal PKI utilising an offlint root and policy server, and an
> AD integrated enterprise issuing server. We've distributed our root
> certificate via a GPO to all workstations/servers in AD.
>
> We have a number of certifcate templates for SSL certs. We permission these
> with Role groups to define who can request and modify the certs.
>
> We have one problematic box, when requesting a certificate via
> servername\certsrv we get a permission denied error:
>
> "An error occurred while creating the certificate request. Please verify
> that your CSP supports any settings you have made and that your input is
> valid.         
> Suggested cause:
> You do not have write permission to save the file to the path        
> Error: 0x00000046 - Permission Denied"
>
> The request is for a generic SSL certificate so that a secure channel can be
> used to communicate between 2 boxes. The certificate request never reaches
> the enterprise issuing server (no record of failed request). The error
> message indicates a permission issue, but the way we permission the templates
> is such that you wont see the cert via the web interface if your not a member
> of the group which can request this certificate type. The user requesting the
> certificate is a member of builtin\administrators of the box requesting the
> certificate.
>
> Anyone have any suggestions?

Similar ThreadsPosted
requesting a certificate in Vista. February 6, 2008, 1:54 pm
Exec.exe requesting operation. Want to block it. January 31, 2007, 1:59 pm
Requesting certificate via certreq.exe to remote CA January 24, 2008, 12:21 pm
RPC Server Unavailable When Requesting Computer Certificate September 16, 2005, 7:07 am
requesting cert from local CA: "no trusted certificate authorities available" November 6, 2006, 12:58 pm
"include in CDP" extention error - Reproducible error: March 4, 2008, 9:42 pm
Certificates March 22, 2007, 12:05 pm
Certificates September 18, 2007, 12:29 am
certificates December 29, 2007, 11:29 pm
Using Certificates for 802.1x and VPN accecss June 29, 2005, 12:25 pm

The site map in XML format XML site map

Contact Us | Privacy Policy