Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

import Windows 2008 certificates from new sister company in different forest

Posted on 2012-03-22
2
Medium Priority
?
246 Views
Last Modified: 2012-03-23
Hello.

I need some guidance on how to import Windows 2008 certificates. My company is small and has a simple Win2008 R2 domain with a single root CA on Win2008 R2. We were just purchased by a large company with root and intermediate CA's, I think on Win2003 R2.

They have their own forest and I have my own forest, which are totally separate. First, we set up an MPLS dedicated T1 circuit between our two companies, and then we established a two-way domain trust. Now, we can see and access each other's servers across the MPLS.

Now, we want to trust each other's Windows certificates, but I'm not sure exactly how to do it. They have provided me with AcmeCorp.cer, AcmeCorpCA.p7b, AcmeCorp-Enterprise-CA.cer and AcmeCorp-IntermediateCA1.cer files.

I went into the Certificates MMC and see an Import option under Trusted Root Certification Autorities, Enterprise Trust, etc. But I'm not sure which certificate goes where, or if I'm even in the right place.

Thanks.
0
Comment
Question by:JohnValue
2 Comments
 
LVL 17

Accepted Solution

by:
James Haywood earned 500 total points
ID: 37756177
Import them all into Trusted Root Certification Authorities.

To deploy these certificates out to all your machines use the GPO setting:

\\computer configuration\Windows Settings\Security Settings\Public Key Polices\Trusted Publishers

Import all 4 Certs following the wizard.
0
 

Author Closing Comment

by:JohnValue
ID: 37757131
Your solution worked. Thanks.

Specifically, I clicked on the "Certificates" folder under "Trusted Root Certification Authorities", right-click, "All Tasks", "Import". In the Wizard, I selected "Automatically select the certificate store based on the type of certificate" for all four certificates.
Only the AcmeCorpCA and IntermediateCA1 appeared, and only in the "Certificates" folder under "Intermediate Certification Authories". Also, to see them I had the click on each "Certificates" folder and click the refresh button.

Then I went into the Default Domain Policy and imported the certificates as you specified. The AcmeCorpCA.p7b didn't show up in the Trusted Publishers folder, though it said it was successfully imported.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question