Solved

Certificate Services with Enterprise Root and Subject Alternative Name for Web Servers

Posted on 2011-03-10
2
1,297 Views
Last Modified: 2012-06-27
I am trying to get certificates with Subject Alternative Names going in my enterprise. I currently have an enterprise root CA running on Windows 2003 R2 Enterprise. The CA cert has been imported to all of my domain members via group policy years ago. That is working fine. I have a new Windows 2008 R2 Enterprise server which is a subordinate (enterprise?) CA. What I need to be able to do is issue Web Server and Computer certificates with Subject Alternative Names for some web servers and other servers related to Remote Desktop Gateway and Session Host servers.

The Technet Article "How to Request a Certificate With a Custom Subject Alternative " <http://technet.microsoft.com/en-us/library/ff625722(WS.10).aspx> says that I should not enable EDITF_ATTRIBUTESUBJECTALTNAME2 because it's a security problem for Enterprise CAs.

When following the instructions for Certificate Enrollment wizard with an enterprise CA, the Web Server Certificate is not available. Only the Computer template is available. It says that I don't have permissions to request the other certificate types.

When I have my new subordinate CA running, my plan is to power down my W2K3R2 root CA.
0
Comment
Question by:kevinhsieh
2 Comments
 
LVL 38

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 35143400
You need to make sure you have permission to enroll web certificates on your CA. If you are a domain admin or enterprise admin, you should already have permission, but to check, run MMC on your CA and open the Certificate Templates snap-in. Find the Web Server certificate in the list, right click, select properties, then go to the security tab and make sure your account or a group you belong to has Enroll permission.
0
 
LVL 42

Author Closing Comment

by:kevinhsieh
ID: 35162449
Well, you were close. As an Enterprise Admin, I had permissions to the template. I could enroll a a web server certificate from IIS, but not from the local certificate manager. It turns out that the MACHINE needed permissions to the template. I created a new group in AD, added the appropriate servers, and then gave that group permission to enroll the certificate. I was then able to do it successfully after rebooting the machines.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Suggested Solutions

When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now