Groups | Blog | Home
all groups > iis security > june 2007 >

iis security : Access Denied: Obtaining a Server Certificate from Your Own CA


overthetop
6/8/2007 12:24:43 PM
Hi

I'm running windows xp and i'm trying to get a web server cert (to run
ssl) from a CA installed on my network on windows 2003.
The CA on the win 2003's machine is working because i've managed to
install a cert on the iis on that machine, but when i try to make a
cert request from my xp machine to that CA at the end of the iis
request cert wizard i get "Failed to install certificate. Access
denied.". Am I doing something wrong? How can I make it right?
I follow this tutorial: http://www.petri.co.il/configure_ssl_on_your_website_with_iis.htm
and after step 15 i get the fail message.
Ken Schaefer
6/11/2007 12:00:00 AM
What happens if you choose to "save the request and submit it later"?

And then you submit the request manually to the Certificate Server? and then
manually approve the certificate?

Cheers
Ken


--
My IIS Blog: www.adOpenStatic.com/cs/blogs/ken

[quoted text, click to view]
overthetop
6/11/2007 12:00:00 AM
On Jun 11, 8:05 am, "Ken Schaefer" <kenREM...@THISadOpenStatic.com>
[quoted text, click to view]

Hi Ken

I submitted the request manually and installed the cert on my computer
successfully but there is a new problem now. The SSL is still not
working. When I browse a site on my iis the browser won't accept the
web server cert that I've just installed?! FireFox tells me that can
not establish encrypted connection to the web server because the
certificate is invalid or corrupted: Error Code -8101 and after
clicking ok the page is not displayed. When I try the same thing with
IE it tells me that the page can not be found and no warning.
What is the problem with this cert? It's installed on the server and
no error till I browse https://...
I request the cert by browsing the CA server: http://CAServer/certsrv
and follow the steps, then download it and install it on the web
server.
overthetop
6/11/2007 12:00:00 AM
[quoted text, click to view]

Is it possible that the problem is in the CA server? When I installed
the CA service I didn't change nothing in the config and now it's
running with default settings. Is there something that needs to be
configured?
AddThis Social Bookmark Button