requesting cert from local CA:

requesting cert from local CA: "no trusted certificate authorities available"

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
requesting cert from local CA: "no trusted certificate authorities available" Jason Viers 11-06-2006
Posted by Jason Viers on November 6, 2006, 12:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm playing around with AD, certificates, and smart cards on a test
server separated from the rest of our network. I'm currently going by
http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/howto/mapcerts.mspx,
trying to get a certificate that I can place on my smart card to log in
with.

I have a certificate authority installed on this domain controller (as a
stand-alone root CA), and I can see its cert in "Trusted Root
Certificate Authorities". If I try to launch the "Request New
Certificate" wizard for any account, I get an error message saying the
wizard could not be started because "there are no trusted certificate
authorities available", or permission is denied.

Is there something special I have to do to get the local machine to
"trust" this CA, or some other way I should go about this?

Thanks
Bean

Posted by Paul Adare on November 7, 2006, 8:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
says...

> I have a certificate authority installed on this domain controller (as a
> stand-alone root CA), and I can see its cert in "Trusted Root
> Certificate Authorities". If I try to launch the "Request New
> Certificate" wizard for any account, I get an error message saying the
> wizard could not be started because "there are no trusted certificate
> authorities available", or permission is denied.
>
> Is there something special I have to do to get the local machine to
> "trust" this CA, or some other way I should go about this?
>

To use the MMC wizard your CA needs to be an Enterprise CA, and not a
standalone.

--
Paul Adare - MVP Virtual Machines
Waiting for a bus is about as thrilling as fishing,
with the similar tantalisation that something,
sometime, somehow, will turn up. George Courtauld


Posted by Jason Viers on November 8, 2006, 5:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Paul Adare wrote:
> To use the MMC wizard your CA needs to be an Enterprise CA, and not a
> standalone.

Thanks, removing the standalone CA and using an Enterprise CA worked!

I was able to request a certificate, export it, and throw it on the
smart card (with private key). When trying to log in, I can insert the
card and it asks for the PIN, but then says

The system could not log you on. The server authenticating you reported
an error (0xC00000BB). See the EventLog for more information.

In the EventLog is the following error:

An error occurred while retrieving a digital certificate from the
inserted smartcard. The keyset is not defined. Data: 19000980

This is all taking place on a single Windows 2003 Enterprise box, so the
documents I see about XP SP2 causing problems
(http://support.microsoft.com/kb/891849) don't apply.

I can look on the smartcard (using the ActivClient Agent software) and
see that the certificate is there, it's been "made available to
Windows", and been set as the primary certificate.

Any ideas what's causing this?

Similar ThreadsPosted
List of trusted authorities - invalid? November 4, 2008, 11:13 am
Commercial cert vs. Microsoft Certificate Services generated cert June 21, 2007, 4:23 am
requesting a certificate in Vista. February 6, 2008, 1:54 pm
Requesting certificate via certreq.exe to remote CA January 24, 2008, 12:21 pm
RPC Server Unavailable When Requesting Computer Certificate September 16, 2005, 7:07 am
Re: EFS Certificate Self Signed Vs. User Cert May 26, 2005, 12:28 am
How Can I Add Local and Network Drive Letters to MSIE Trusted Sites Security Zone? October 15, 2007, 12:40 am
Root CA cert expires, I renewed but I'm unable to request new cert March 7, 2006, 3:16 pm
Computer cert/User cert 802.x Authentication query August 7, 2007, 5:20 am
Local Certificate Authority Server July 7, 2006, 1:53 am

The site map in XML format XML site map

Contact Us | Privacy Policy