SAN Certificate request not being accepted, refreshes page with blank fields without any error


hi,

i have created 2 tier ca using win2008 r2 (inf files used create standalone root , enterprise subca @ end of post).

the root installed ok , issued certificate subca, subca has in turn issued certificates domain controllers automatically.

my pki health green chains valid , crl's published.

however when try , register san certificate exchange server request not accepted, infact there no error message. following (http://exchangeserverpro.com/how-to-issue-a-san-certificate-to-exchange-server-2010-from-a-private-certificate-authority) , in summary:

1) exchange power shell: new-exchangecertificate -friendlyname "exchange 2010 certificate" -includeserverfqdn -domainname mail.mydomain.net,autodiscover.mydomain.net,webmail.mydomain.net -generaterequest -privatekeyexportable $true
2) goto sub ca web certificate services http://subca/certsvc
3) request certificate
4) submit advanced certificate request
5) submit certificate request using base-64-encoded cmc or pkcs #10 file
6) paste request step 1 in saved request box
7) select certificate type web server
8) hit submit
9) nothing... page refeshes show same page again. there no error on page or in log, , request not submitted.

i have tried submitting cer file subordinate ca via certsrv mmc, right click ca -> tasks -> submit new request -> select cer file, , hit ok. nothing happens, no error, no pending request, there nothing in logs, nothing.

any ideas doing wrong?

thanks in advance,

chris

; capolicy.inf example file root ca
[version]
signature= "$windows nt$"

renewalkeylength=2048
renewalvalidityperiod=years
renewalvalidityperiodunits=20

crlperiod = years
crlperiodunits = 1
crldeltaperiod = days
crldeltaperiodunits = 0

alternatesignaturealgorithm=1

[crldistributionpoint]
empty=true

[authorityinformationaccess]
empty=true

; capolicy.inf file issuing ca
[version]
signature= "$windows nt$"

[certsrv_server]
renewalkeylength=2048
renewalvalidityperiod=years
renewalvalidityperiodunits=10

crlperiod=weeks
crlperiodunits=1

crldeltaperiod=days
crldeltaperiodunits=1

crloverlapperiod=days
crloverlapunits=2

validityperiod=years
validityperiodunits=2

alternatesignaturealgorithm=1



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL