| Author |
Message |
Tony Su
Guest
|
Posted:
Thu Feb 24, 2005 4:21 am Post subject:
What are Certificate requirements? |
|
|
IIRC, Docs describe only the requirement to be validated and support TLS.
Purchased a commercial certificate, but installing the certificate generates
the following error
Live Communications Server requires a certificate that has a private key.
Please select a new one.
What is this private key required to do?
Is there a specific laundry list of requirements I can use in requesting a
certificate?
TIA,
--
Tony Su
www.su-networking.com
ISA
SBS
Enterprise Mobile Solutions Architect |
|
| Back to top |
|
 |
S. Pidgorny
Guest
|
Posted:
Thu Feb 24, 2005 2:29 pm Post subject:
Re: What are Certificate requirements? |
|
|
Private key is required to decrypt traffic that is encrypted with the public
key. Signed public key is the certificate. Further information and links
please find at http://en.wikipedia.org/wiki/Pki
The error message that you're getting is self-explanatory: you don't have
the private key in the store where you have installed the certificate. As
such, you won't be able to use the certificate for any TLS function, or even
export if to a PKCS #12 file.
Which commercial CA have you used to request the certificate, what type of
certificate have you chosen and how exactly have you enrolled? It is only
possible to provide detailed help having those details.
--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =- |
|
| Back to top |
|
 |
Tony Su
Guest
|
Posted:
Fri Feb 25, 2005 2:29 am Post subject:
Re: What are Certificate requirements? |
|
|
Hmmm...
I thought I had purchased the correct certificate, now I'm reading the cert
description again and ai don't see what I thought I saw before (GoDaddy High
Assurance Certificate)
https://www.godaddy.com/gdshop/ssl/high.asp?se=%2B&app%5Fhdr=
I received a second certificate I haven't installed yet, am not sure whether
this other certificate is what is required. Is the Private Key supposed to be
embedded in the current certificate or in another certificate?
Tony |
|
| Back to top |
|
 |
S. Pidgorny
Guest
|
Posted:
Fri Feb 25, 2005 1:43 pm Post subject:
Re: What are Certificate requirements? |
|
|
Tony,
the private key is never sent to the CA - if you're using Windows client to
enrol for the cert, the private key is on that system, perhaps - in the user
certificate store.
I wasn't able to get to the enrollment at GoDaddy - they ask for the credit
card details first. You might wish to call their support and get
step-by-step instructions.
Usually you have to mark private keys as exportable during the enrollment,
and after receiving the cert - export it to a PKCS #12 (.pfx/.p12) file, and
import it on the server. But, again, you better get instructions from the
vendor.
--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =- |
|
| Back to top |
|
 |
Tony Su
Guest
|
Posted:
Fri Feb 25, 2005 7:47 pm Post subject:
Re: What are Certificate requirements? |
|
|
Thx, I'll see what can be done. Will post back results if I can get this
resolved.
Tony |
|
| Back to top |
|
 |
Tony Su
Guest
|
Posted:
Sat Feb 26, 2005 6:48 am Post subject:
Re: What are Certificate requirements? |
|
|
GoDaddy says that all their certificates cannot be used for TLS, only for SSL.
Any suggestions from anybody on a Commercial CA who issues certificates
which can be used for TLS (LCS)?
Tony |
|
| Back to top |
|
 |
Greg
Guest
|
Posted:
Fri Mar 04, 2005 2:48 am Post subject:
Re: What are Certificate requirements? |
|
|
| We got our certificates from VeriSign and they work for TLS. |
|
| Back to top |
|
 |
S. Pidgorny
Guest
|
Posted:
Fri Mar 04, 2005 2:44 pm Post subject:
Re: What are Certificate requirements? |
|
|
| Quote: | GoDaddy says that all their certificates cannot be used for TLS, only for
SSL. |
That means they don't know what they are talking about. I have visited their
site with TLS 1.0 only enabled and SSL 2.0 and 3.0 disabled in IE security
options - it works (and EKUs are right for LCS).
However, provided their ignorance in the matter, I'd better turn to more
reliable source. Like Thawte (https://www.thawte.com)
--
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =- |
|
| Back to top |
|
 |
Tony Su
Guest
|
Posted:
Tue Mar 08, 2005 6:49 am Post subject:
Re: What are Certificate requirements? |
|
|
Yeah,
I have since discovered that <every> CA in the authentication chain has to
be configured individually and manually to make things work, it's not
sufficient to configure only the cert installed into LCS.
And, after I determined that was the issue I went back and looked at
GoDaddy's cert and saw that it should work, too.
Thx all for posting,
Tony |
|
| Back to top |
|
 |
lozzmo
Joined: 17 Aug 2006
Posts: 1
|
Posted:
Thu Aug 17, 2006 3:10 am Post subject:
|
|
|
Tony, can you please let me know what you did to fix it? We just installed LCS, have a GoDaddy cert, and have exactly the same situation as yourself.
Thanks,
Lozzmo |
|
| Back to top |
|
 |
|
|
|
|