?
Solved

PrivateKeyMissing

Posted on 2011-09-21
6
Medium Priority
?
355 Views
Last Modified: 2012-05-12
I installed Exchange 2010 with SP1 rollup 5 on 2K8 R2 server and am having the following certificate issues.

I have a separate AD server with AD Certificate Services installed to issue certificates.
I generated the request from the EMC for a wildcard certificate, open up the file and copy the contents and paste it into the web based certificate request form from AD server. It creates two cert files, certnew.cer and certnew.p7b.
I use the MMC for Certificates and install the certnew.p7b in the Intermediate Certificate Authorities, then go to the EMC to complete the pending request. It appears to install correctly, but then disappears from the EMC.
I found on this site where others said the GUI is flakey, so I followed the commands using the  Exchange Management Shell from this http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_26722561.html It returns the following error...
The certificate with thumbprint blahblahblah was found but is not valid for use with Exchange Server (reason: PrivateKeyMissing)

Where did I go wrong and how can I fix?
0
Comment
Question by:pjmac28
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 8

Expert Comment

by:Shmoid
ID: 36576833
In the steps you outlined in your post you said you used the .p7b file to install the Certificate Authority. But when you go back to the EMC you didn't specify if you used the .p7b file or the .cer file. If you are using the .p7b file it will not work. You must use the .cer file.
0
 

Author Comment

by:pjmac28
ID: 36577197
Correct, I used the .cer file with the EMC & EMS...sorry for not clarifying.
0
 
LVL 8

Accepted Solution

by:
Shmoid earned 2000 total points
ID: 36577823
Try removing the autodiscovery entries before creating the CSR. See this post for more info:

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_26898487.html
0
Bringing Advanced Authentication to the SMB Market

WatchGuard announces the acquisition of advanced authentication provider, Datablink, with one mission – to bring secure authentication to SMB, mid-market, and distributed enterprises with a cloud-based solution, ideal for resale via their established channel & MSSP community.

 

Author Comment

by:pjmac28
ID: 36580524
The certificate installed, but now shows under the status of the EMC that it is invalid for Exchange Server usage.

When I submitted it to the web based request form, I selected Web Server as the Certificate Template, as the other options are: User, Basic EFS, Administrator, EFS Recovery Agent, Subordinate Certification Authority.
0
 

Author Comment

by:pjmac28
ID: 36580686
When I look at the properties of the installed certificate, it displays: This certificate cannot be verified up to a trusted certification authority.
0
 

Author Comment

by:pjmac28
ID: 36580727
I just install the .p7b file to the Trusted Root Certification Authorities folder in the Certificates Console and now the certificate show in EMC as valid. :)
0

Featured Post

Ransomware Attacks Keeping You Up at Night?

Will your organization be ransomware's next victim?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with our Ransomware Prevention Kit!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We've all had that page pop up telling us there is a problem with the certificate and some of us continue on anyways and others run away to a safer competing site.  But what to do when you get the error - is it your problem or theirs?  What can you …
#SSL #TLS #Citrix #HTTPS #PKI #Compliance #Certificate #Encryption #StoreFront #Web Interface #Citrix XenApp
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question