Solved

import Windows 2008 certificates from new sister company in different forest

Posted on 2012-03-22
2
240 Views
Last Modified: 2012-03-23
Hello.

I need some guidance on how to import Windows 2008 certificates. My company is small and has a simple Win2008 R2 domain with a single root CA on Win2008 R2. We were just purchased by a large company with root and intermediate CA's, I think on Win2003 R2.

They have their own forest and I have my own forest, which are totally separate. First, we set up an MPLS dedicated T1 circuit between our two companies, and then we established a two-way domain trust. Now, we can see and access each other's servers across the MPLS.

Now, we want to trust each other's Windows certificates, but I'm not sure exactly how to do it. They have provided me with AcmeCorp.cer, AcmeCorpCA.p7b, AcmeCorp-Enterprise-CA.cer and AcmeCorp-IntermediateCA1.cer files.

I went into the Certificates MMC and see an Import option under Trusted Root Certification Autorities, Enterprise Trust, etc. But I'm not sure which certificate goes where, or if I'm even in the right place.

Thanks.
0
Comment
Question by:JohnValue
2 Comments
 
LVL 17

Accepted Solution

by:
James Haywood earned 125 total points
ID: 37756177
Import them all into Trusted Root Certification Authorities.

To deploy these certificates out to all your machines use the GPO setting:

\\computer configuration\Windows Settings\Security Settings\Public Key Polices\Trusted Publishers

Import all 4 Certs following the wizard.
0
 

Author Closing Comment

by:JohnValue
ID: 37757131
Your solution worked. Thanks.

Specifically, I clicked on the "Certificates" folder under "Trusted Root Certification Authorities", right-click, "All Tasks", "Import". In the Wizard, I selected "Automatically select the certificate store based on the type of certificate" for all four certificates.
Only the AcmeCorpCA and IntermediateCA1 appeared, and only in the "Certificates" folder under "Intermediate Certification Authories". Also, to see them I had the click on each "Certificates" folder and click the refresh button.

Then I went into the Default Domain Policy and imported the certificates as you specified. The AcmeCorpCA.p7b didn't show up in the Trusted Publishers folder, though it said it was successfully imported.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We recently had an issue where out of nowhere, end users started indicating that their logins to our terminal server were just showing a "blank screen." After checking the usual suspects -- profiles, shell=explorer.exe in the registry, userinit.exe,…
Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question