clm users certificates expiration

clm users certificates expiration

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
clm users certificates expiration =?Utf-8?B?VW5haSBDYXN0cm8=?= 03-30-2008
Posted by =?Utf-8?B?VW5haSBDYXN0cm8=?= on March 30, 2008, 5:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

What happend when clm users (clmagent, clmkragent and clmenrollanget)
certificates expired? CLM can renew this users certificates or I need request
renew for this users?

Regards,
--
Unai Castro
MCP Windows 2003, XP, Exhcange 2003

Posted by Brian Komar \(MVP\) on March 30, 2008, 7:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
There are two different ways used:
1) Verify that the clm.config.exe.config file references the correct CSP
used for the agent certificates (You may change it if using an HSM to
protect the keys). Then run the configuration wizard again. This does
involve retyping all agent passwords, but will issue new certificates for
the three agent accounts. The wizard will update the web.config file. You
will have to verify that the correct KRA certificates is available at all
enterprise CAs in the environment. (and may have to delete the
expired/expiring certificate).

2) Log in as each clmAgent and renew the certificate manually. Once renewed,
you must update the web.config file with the new thumbprint of the new
certificates. Pnly the clmenrollagent and clmagent accounts have references
in the web.config file. The key is to search for the words "hash" and
"hashes". In the case of "hash", replace the current value with the new
thumbprint (removing the spaces). In the case of hashes, add the new
thumbprint (removing the spaces), separated by commas (may be semi-colons,
check the comments above the line.

HTH,
Brian

> Hello,
>
> What happend when clm users (clmagent, clmkragent and clmenrollanget)
> certificates expired? CLM can renew this users certificates or I need
> request
> renew for this users?
>
> Regards,
> --
> Unai Castro
> MCP Windows 2003, XP, Exhcange 2003


Posted by =?Utf-8?B?VW5haSBDYXN0cm8=?= on April 1, 2008, 7:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you Brian. I test two ways and both works.

--
Unai Castro
MCP Windows 2003, XP, Exhcange 2003


"Brian Komar (MVP)" wrote:

> There are two different ways used:
> 1) Verify that the clm.config.exe.config file references the correct CSP
> used for the agent certificates (You may change it if using an HSM to
> protect the keys). Then run the configuration wizard again. This does
> involve retyping all agent passwords, but will issue new certificates for
> the three agent accounts. The wizard will update the web.config file. You
> will have to verify that the correct KRA certificates is available at all
> enterprise CAs in the environment. (and may have to delete the
> expired/expiring certificate).
>
> 2) Log in as each clmAgent and renew the certificate manually. Once renewed,
> you must update the web.config file with the new thumbprint of the new
> certificates. Pnly the clmenrollagent and clmagent accounts have references
> in the web.config file. The key is to search for the words "hash" and
> "hashes". In the case of "hash", replace the current value with the new
> thumbprint (removing the spaces). In the case of hashes, add the new
> thumbprint (removing the spaces), separated by commas (may be semi-colons,
> check the comments above the line.
>
> HTH,
> Brian
>
> > Hello,
> >
> > What happend when clm users (clmagent, clmkragent and clmenrollanget)
> > certificates expired? CLM can renew this users certificates or I need
> > request
> > renew for this users?
> >
> > Regards,
> > --
> > Unai Castro
> > MCP Windows 2003, XP, Exhcange 2003
>
>

Posted by Paul Adare on March 30, 2008, 8:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sun, 30 Mar 2008 02:39:00 -0700, Unai Castro wrote:

> What happend when clm users (clmagent, clmkragent and clmenrollanget)
> certificates expired? CLM can renew this users certificates or I need request
> renew for this users?

CLM actually doesn't manage these certificates. If you think about, it
can't, since the certificates are issued before your CLM deployment is
functioning. You need to manually renew these certificates outside of CLM
and then update web.config with the new thumbprints for the clmAgent and
clmEnrollAgent certificates.


--
Paul Adare
MVP - Virtual Machines
http://www.identit.ca
A list is only as strong as its weakest link. -- Don Knuth

Posted by =?Utf-8?B?VW5haSBDYXN0cm8=?= on March 30, 2008, 2:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you Paul. I thought that CLM server request certificates renew like
when it's configured at first time.
--
Unai Castro
MCP Windows 2003, XP, Exhcange 2003


"Paul Adare" wrote:

> On Sun, 30 Mar 2008 02:39:00 -0700, Unai Castro wrote:
>
> > What happend when clm users (clmagent, clmkragent and clmenrollanget)
> > certificates expired? CLM can renew this users certificates or I need
request
> > renew for this users?
>
> CLM actually doesn't manage these certificates. If you think about, it
> can't, since the certificates are issued before your CLM deployment is
> functioning. You need to manually renew these certificates outside of CLM
> and then update web.config with the new thumbprints for the clmAgent and
> clmEnrollAgent certificates.
>
>
> --
> Paul Adare
> MVP - Virtual Machines
> http://www.identit.ca
> A list is only as strong as its weakest link. -- Don Knuth
>

Similar ThreadsPosted
Re: Expiration Of Certificates July 11, 2005, 8:32 am
Password Expiration for Remote Users March 16, 2006, 1:07 pm
Remote users and Password expiration October 10, 2006, 11:30 am
Deleting Archived Certificates from Users' My store on Workstations July 8, 2008, 3:50 pm
On password expiration March 31, 2006, 1:51 am
PKI - Certificate expiration notifications November 8, 2007, 12:27 am
Credential expiration timestamps and groups January 10, 2007, 10:59 am
Preventing Kerberos Ticket Expiration December 26, 2007, 11:23 am
Service accounts with password expiration August 15, 2008, 2:36 pm
password expiration policy for admin and system accounts ? October 19, 2005, 6:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy