New SHA256 PKI - Error installing approved/issued certificate


i stood two-tier sha256 microsoft ad cs pki offline standalone root , enterprise subordinate ca.  seems good:  enterprise pki mmc snap-in on clients checked shows "ok" next components of new pki.

i'm trying issue first sha256 certificate issuing ca purpose of using tls web enrollment site, i'm having trouble.

on new issuing ca, have single certificate template published.  it's v3 template modified our standard v2 template used https.  modifications original template compatibility has changed windows server 2012 r2 / windows 7, provider category has been changed key storage provider, , request hash has changed sha256.

since v3 template (and since server doesn't have server authentication certificate issued yet), can't use web enrollment certificate, enrolled through certificates mmc.  template requires administrative approval, went , approved pending request.  after this, went certificate enrollment requests section of certificates mmc , downloaded associated certificate file "cert.cer".  after this, ran command "certreq.exe -accept cert.cer" , receive error message: "certificate request processor: certificate chain processed, terminated in root certificate not trusted trust provider. 0x800b0109 (-2146762487 cert_e_untrustedroot)"

i not sure why getting error message.  new root ca's certificate in trusted root certificates store on issuing ca , issuing ca's certificate appears trusted issuing ca itself.

i'm used using web enrollment everything, i'm trying figure out process should new sha256 certificates , how systems administrators can create own enrollment requests , install issued certificates without using web enrollment (certsrv) site.  had seen suggest method tried, not seem work or there problem.

any , assistance welcome.  in advance!


did run certreq -retrieve [requestid] [outputfile] prior running certreq -accept?

you have download certificate first (retrieve) before can associate key pair (accept)

brian



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL