Solved

Installing site server Certificate for SCCM

Posted on 2012-04-06
4
1,977 Views
Last Modified: 2012-04-08
I am trying to install SCCM 2012 in a test lab and am trying to import a certificate on the site server by following the instructions outlined here:

http://technet.microsoft.com/en-us/library/cc872789.aspx#BKMK_siteserver12008

I am able to get to the point where it says to " Type the following command, and then press Enter: certreq –accept sitesigning.cer"

When I do that, I receive the following error: "A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. 0x800b0109 (-2146762487)"

I'm not quite sure what to do as I followed all the other instructions.
0
Comment
Question by:max_owen
  • 2
  • 2
4 Comments
 
LVL 17

Expert Comment

by:James Haywood
ID: 37818814
Do you have the Root CA Cert in your Trusted Root Authorities?
0
 

Author Comment

by:max_owen
ID: 37818879
I don't believe so. I was looking into that last night. Is a Root CA Cert a computer certificate from the enterprise CA? I'm not quite sure how to request one.
0
 
LVL 17

Accepted Solution

by:
James Haywood earned 500 total points
ID: 37819989
A Root Cert is the certificate from the CA itself. This has to be trusted to allow any certs it issues  to be trusted. Online authorities (Go daddy, Geo Trust, Globalsign etc) are automatically trusted by Windows as their Root Certificates are installed by default.

To export your Root CA Cert (instructions direct from Microsoft):

 
   a. Logon into Root Certification Authority Web Enrollment Site.
 
     Usually the Web Enrollment Site reside in following links:
 
              http://<ip_address/certsrv or http://fqdn/certsrv
 
               ip_address = Root Certification Authority Server IP.
 
               fqdn =  Fully qualified domain name of the Root Certification Authority Server.
 
   b. Click the "Download a CA certificate, certificate chain, or CRL" link.
 
   c. Press on "Download CA certificate" link.
 
   d. Save the file "certnew.cer" in local disk store.

I usually save the file to desktop. Doubleclick the certificate and select "install certificate", follow the wizard but ensure the cert is saved into the "Trusted Root Certification Authorities" store.
0
 

Author Comment

by:max_owen
ID: 37821257
OK, I tried that but it doesn't appear to actually import. It does not error out during your instructions but when I check the Trusted Root Cert Authorities the cert is not in there. I tried it on my test Windows 7 workstation and it imported fine and I was able to see it in the Trusted Root Cert Authorities. Not sure why it isn't working on my test 2008R2 SCCM server??
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now