Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Certificate Services with Enterprise Root and Subject Alternative Name for Web Servers

Posted on 2011-03-10
2
Medium Priority
?
1,315 Views
Last Modified: 2012-06-27
I am trying to get certificates with Subject Alternative Names going in my enterprise. I currently have an enterprise root CA running on Windows 2003 R2 Enterprise. The CA cert has been imported to all of my domain members via group policy years ago. That is working fine. I have a new Windows 2008 R2 Enterprise server which is a subordinate (enterprise?) CA. What I need to be able to do is issue Web Server and Computer certificates with Subject Alternative Names for some web servers and other servers related to Remote Desktop Gateway and Session Host servers.

The Technet Article "How to Request a Certificate With a Custom Subject Alternative " <http://technet.microsoft.com/en-us/library/ff625722(WS.10).aspx> says that I should not enable EDITF_ATTRIBUTESUBJECTALTNAME2 because it's a security problem for Enterprise CAs.

When following the instructions for Certificate Enrollment wizard with an enterprise CA, the Web Server Certificate is not available. Only the Computer template is available. It says that I don't have permissions to request the other certificate types.

When I have my new subordinate CA running, my plan is to power down my W2K3R2 root CA.
0
Comment
Question by:kevinhsieh
2 Comments
 
LVL 43

Accepted Solution

by:
Adam Brown earned 1500 total points
ID: 35143400
You need to make sure you have permission to enroll web certificates on your CA. If you are a domain admin or enterprise admin, you should already have permission, but to check, run MMC on your CA and open the Certificate Templates snap-in. Find the Web Server certificate in the list, right click, select properties, then go to the security tab and make sure your account or a group you belong to has Enroll permission.
0
 
LVL 42

Author Closing Comment

by:kevinhsieh
ID: 35162449
Well, you were close. As an Enterprise Admin, I had permissions to the template. I could enroll a a web server certificate from IIS, but not from the local certificate manager. It turns out that the MACHINE needed permissions to the template. I created a new group in AD, added the appropriate servers, and then gave that group permission to enroll the certificate. I was then able to do it successfully after rebooting the machines.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question