![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
2003 CA - Trusted Root Certificate Authority?this thread has 5 replies and has been viewed 20380 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||||||
|
||||||||
|
Hi all,
I'm having a problem creating a root trust certificate on a Windows 2003 server running Exchange 2003. I want to use it to configure RPC over HTTP for Outlook clients. I have 4 servers running 2003, one is GC, 2 others are additional domain controllers including the Exchange server. The Exchange server is on the same location as the GC, the other is in another country. The GC is also CA server, while the Exchange server is a subordinate certificate server. I can create a webserver certificate with no problems, but I can't store it in the clients trusted root cert store. When importing it into the clients cert store, using the guide, it's ending up in the "Other people" store. When importing the certificate into the "Trusted Root Certification Authorities" it doesn't show up. I have been using SBS 2003 with RPC over HTTP, where the certificate creation is done by the "Configure Internet and Email" wizard. The clients have no problem downloading and installing these certificates. However, things are not so uncomplicated in a standard Windows 2003 enviroment. I've been working with OpenSSL and Apache on *nix platforms, but I haven't had the same problems that I have here. I've been searching Microsoft's website to find info about this, but I haven't found anything useful. I could of course buy a Verisign certificate or something like that but I don't need that, it's only intended for corporate use. I'm pretty new to certificates in a Windows enviroment. Could anyone point me in the right direction ... brgrds - MrDk |
|
#2
|
||||||||||
|
||||||||||
|
It's not the Webserver cert you need to install on the clients it the issuing CA's server auth If you view the cert details in IE when browsing to your site then I will tell you whcih server is the issuing CA.
Then on this server, on Certifictaes MMC, and find it own cert, export and install on clients. topper
__________________
There are 10 types of people in this world, those who understand binary and those who do not. |
|
#3
|
||||||||
|
||||||||
|
Thanks for the tip, but it doesn't seem to work.
The certificates in this store is deployed by default to domain computers, but doesn't seem to terminate the ssl connection trough IIS. I tried to export the certificates and use them as webserver certs, but it didn't work either. Gotta try something else. brgrds - MrDk |
|
#4
|
||||||||
|
||||||||
|
To my understanding, there is no such thing as RDP over HTTP. I do know of a flavor called tsweb which can secure the "front page". But this does not do any favors as far as encrypting the session. I've had luck with RDP over SSL/TLS1 with SP1 and RDP over HTTPS with R2. May I suggest SELFSSL
It's an easy deployment for 1024 encryption. Keep in mind that the CN must match your machine name. You needn't have the same DC as your A record, however. Keep in touch. I'm playing with the same technology at the moment. |
|
#5
|
||||||||||
|
||||||||||
|
Actually, it is RPC over HTTP and NOT RDP over HTTP.
Click on the red link for more information about it.
__________________
"There I stood at the bar, wearing a Mae West, no jacket, and beginning to leak blood from my torn boot. None of the golfers took any notice of me - after all, I wasn't a member!" Kenneth Lee - after being shot down during the Battle of Britain on the 18th August 1940. ************************************************** ********************** ** Remember to give credit where credit is due and leave reputation points where appropriate ** ************************************************** ********************** |
|
#6
|
||||||||
|
||||||||
|
Here is the detailed procedure you need to follow to get your client system to trust the CA server in your organization:
Anyway, I have also set up RPC over HTTP on the SBS 2003 platform and never experienced this issue. What truly puzzles me is that it doesn't seem as though SBS 2003 even has a CA. The certificate is "self signed" with the external address of the machine and includes all possible permutations of the machine name itself from the inside as well as the external name. This self signed certificate is apparently accepted by IE without the need to add the certificate server to the trusted roots. The questions that are raise are
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| SBS 2003 Certificate on Windows Mobile 5 | Coolmike | SBS 2000 / 2003 | 4 | 16th March 2006 17:18 |
| Office 2003 SP2 is now available | gabriel_buc | Windows Server 2000 / 2003 | 5 | 18th November 2005 20:17 |
| Changing the Certificate on an Exchange 2003 Server | Jerzygags | Exchange 2000 / 2003 | 1 | 22nd September 2005 11:40 |
| Moving to a new root Enterprise Certificate Authority | heyhogan | Windows Server 2000 / 2003 | 0 | 3rd June 2004 19:13 |
| Useful add-ons for MS Project 2003 server | Ossian | Misc | 0 | 21st January 2004 14:07 |