What are Certificate requirements?
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
What are Certificate requirements?

 
Post new topic   Reply to topic    Windows Server Forum Index -> Live Communications Server
Author Message
Tony Su
Guest





Posted: Thu Feb 24, 2005 4:21 am    Post subject: What are Certificate requirements? Reply with quote

IIRC, Docs describe only the requirement to be validated and support TLS.

Purchased a commercial certificate, but installing the certificate generates
the following error

Live Communications Server requires a certificate that has a private key.
Please select a new one.

What is this private key required to do?
Is there a specific laundry list of requirements I can use in requesting a
certificate?

TIA,
--
Tony Su
www.su-networking.com
ISA
SBS
Enterprise Mobile Solutions Architect
Back to top
S. Pidgorny
Guest





Posted: Thu Feb 24, 2005 2:29 pm    Post subject: Re: What are Certificate requirements? Reply with quote

Private key is required to decrypt traffic that is encrypted with the public
key. Signed public key is the certificate. Further information and links
please find at http://en.wikipedia.org/wiki/Pki

The error message that you're getting is self-explanatory: you don't have
the private key in the store where you have installed the certificate. As
such, you won't be able to use the certificate for any TLS function, or even
export if to a PKCS #12 file.

Which commercial CA have you used to request the certificate, what type of
certificate have you chosen and how exactly have you enrolled? It is only
possible to provide detailed help having those details.

--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-
Back to top
Tony Su
Guest





Posted: Fri Feb 25, 2005 2:29 am    Post subject: Re: What are Certificate requirements? Reply with quote

Hmmm...
I thought I had purchased the correct certificate, now I'm reading the cert
description again and ai don't see what I thought I saw before (GoDaddy High
Assurance Certificate)

https://www.godaddy.com/gdshop/ssl/high.asp?se=%2B&app%5Fhdr=

I received a second certificate I haven't installed yet, am not sure whether
this other certificate is what is required. Is the Private Key supposed to be
embedded in the current certificate or in another certificate?

Tony
Back to top
S. Pidgorny
Guest





Posted: Fri Feb 25, 2005 1:43 pm    Post subject: Re: What are Certificate requirements? Reply with quote

Tony,

the private key is never sent to the CA - if you're using Windows client to
enrol for the cert, the private key is on that system, perhaps - in the user
certificate store.

I wasn't able to get to the enrollment at GoDaddy - they ask for the credit
card details first. You might wish to call their support and get
step-by-step instructions.

Usually you have to mark private keys as exportable during the enrollment,
and after receiving the cert - export it to a PKCS #12 (.pfx/.p12) file, and
import it on the server. But, again, you better get instructions from the
vendor.

--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-
Back to top
Tony Su
Guest





Posted: Fri Feb 25, 2005 7:47 pm    Post subject: Re: What are Certificate requirements? Reply with quote

Thx, I'll see what can be done. Will post back results if I can get this
resolved.

Tony
Back to top
Tony Su
Guest





Posted: Sat Feb 26, 2005 6:48 am    Post subject: Re: What are Certificate requirements? Reply with quote

GoDaddy says that all their certificates cannot be used for TLS, only for SSL.

Any suggestions from anybody on a Commercial CA who issues certificates
which can be used for TLS (LCS)?

Tony
Back to top
Greg
Guest





Posted: Fri Mar 04, 2005 2:48 am    Post subject: Re: What are Certificate requirements? Reply with quote

We got our certificates from VeriSign and they work for TLS.
Back to top
S. Pidgorny
Guest





Posted: Fri Mar 04, 2005 2:44 pm    Post subject: Re: What are Certificate requirements? Reply with quote

Quote:
GoDaddy says that all their certificates cannot be used for TLS, only for
SSL.

That means they don't know what they are talking about. I have visited their
site with TLS 1.0 only enabled and SSL 2.0 and 3.0 disabled in IE security
options - it works (and EKUs are right for LCS).

However, provided their ignorance in the matter, I'd better turn to more
reliable source. Like Thawte (https://www.thawte.com)

--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-
Back to top
Tony Su
Guest





Posted: Tue Mar 08, 2005 6:49 am    Post subject: Re: What are Certificate requirements? Reply with quote

Yeah,
I have since discovered that <every> CA in the authentication chain has to
be configured individually and manually to make things work, it's not
sufficient to configure only the cert installed into LCS.

And, after I determined that was the issue I went back and looked at
GoDaddy's cert and saw that it should work, too.

Thx all for posting,
Tony
Back to top
lozzmo



Joined: 17 Aug 2006
Posts: 1

Posted: Thu Aug 17, 2006 3:10 am    Post subject: Reply with quote

Tony, can you please let me know what you did to fix it? We just installed LCS, have a GoDaddy cert, and have exactly the same situation as yourself.

Thanks,

Lozzmo
Back to top
View user's profile Send private message
 
Post new topic   Reply to topic    Windows Server Forum Index -> Live Communications Server All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB