Sign in
Windows PKI blog
News and information for public key infrastructure (PKI) and Active Directory Certificate Services (AD CS) professionals
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
A Certificate could not be created
Active Directory Domain Services
AD CS
AD CS documentation updates
architecture
Backup Private Keys ADCS 2008 R2 p12 CA
CA
CA maintenance
certificate
certificate requests
certificates
Certification authority
certifiication authority
certutil
Configuration
CRL
cryptography
Data Recvoery
Homeland Security Presidential Directive 12
HSPD-12
key management
PKI
setup
SHA2 NIST SP800-78-2 SP800-57
whitepaper
Archive
Archives
May 2013
(1)
March 2013
(3)
December 2012
(3)
October 2012
(1)
August 2012
(1)
July 2012
(1)
June 2012
(3)
May 2012
(2)
April 2012
(2)
March 2012
(2)
February 2012
(1)
January 2012
(2)
December 2011
(1)
October 2011
(3)
September 2011
(2)
August 2011
(3)
June 2011
(2)
March 2011
(2)
February 2011
(3)
September 2010
(1)
August 2010
(3)
June 2010
(2)
May 2010
(2)
April 2010
(2)
March 2010
(2)
February 2010
(1)
January 2010
(2)
December 2009
(2)
November 2009
(2)
October 2009
(2)
September 2009
(7)
August 2009
(10)
July 2009
(1)
June 2009
(2)
May 2009
(2)
April 2009
(2)
February 2009
(1)
January 2009
(4)
December 2008
(2)
October 2008
(3)
September 2008
(1)
July 2008
(1)
June 2008
(1)
May 2008
(1)
April 2008
(1)
February 2008
(2)
January 2008
(1)
November 2007
(1)
October 2007
(1)
September 2007
(1)
August 2007
(2)
July 2007
(2)
May 2007
(2)
April 2007
(1)
February 2007
(4)
January 2007
(1)
December 2006
(3)
November 2006
(1)
TechNet Blogs
>
Windows PKI blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows PKI blog
Does Enterprise PKI (PKIVIEW) support OCSP?
Posted
over 2 years ago
by
Kurt L Hudson MSFT
0
Comments
A common question from certification authority administrators is "Does Enterprise PKI (PKIView) support OCSP?" Yes, the Microsoft Management Console (MMC) Enterprise PKI ( PKIView ), supports the When setting up Certificate Extensions, you must ensure...
Windows PKI blog
Updated requirements for a Windows Server 2008 R2 domain controller certificate from a 3rd party CA
Posted
over 2 years ago
by
Kurt L Hudson MSFT
2
Comments
Ingolfur has written a blog post as well as a TechNet Wiki article describing how a Windows Server 2008 R2 certification authority (CA) parses certificates, especially those from a third-party (3rd party) non-Microsoft CA. He also covers the Key Distribution...
Windows PKI blog
Windows 8 Developer Preview and AD CS / PKI: Cannot Get a Certificate from Web
Posted
over 2 years ago
by
Kurt L Hudson MSFT
3
Comments
If you are using Windows Developer Preview and have difficulty obtaining or downloading a certificate using Internet Explorer 10 (IE 10), try using compatibility mode. Turning on Compatibility View is the same in IE10 as in IE9, so you can follow the...
Windows PKI blog
Internet Explorer 9 and Certificate Enrollment using Certificate Authority Web Enrollment
Posted
over 2 years ago
by
Kurt L Hudson MSFT
1
Comments
If you run into an issue where you are unable to download or save certificates using Internet Explorer 9 (IE 9) and the Certificate Authority Web Enrollment service of a certification authority, you should be sure to disable the enhanced security option...
Windows PKI blog
Active Directory Certificate Services Frequently Asked Questions - needs your help!
Posted
over 2 years ago
by
Kurt L Hudson MSFT
4
Comments
If you have commonly asked questions about certificate services or PKI that you think should be listed in the Active Directory Certificate Services Frequently Asked Questions (AD CS FAQ ) list, I encourage you to submit them to the TechNet Wiki posting...
Windows PKI blog
AD CS Content Updates
Posted
over 2 years ago
by
Kurt L Hudson MSFT
0
Comments
The following documentation updates have been recently made: AD CS: Deploying Cross-forest Certificate Enrollment - updated with a link to the download center version of the document Additional documents added to the "future" consolidated download...
Windows PKI blog
Important Security Update for Windows Server: Active Directory Certificate Services Web Enrollment!
Posted
over 2 years ago
by
Kurt L Hudson MSFT
1
Comments
An important security update, described in MS11-051 ( http://go.microsoft.com/fwlink/?LinkId=217101 ) was released today. The update fixes a cross-site scripting vulnerability in the sample web enrollment ASP pages that are part of Active Directory Certificate...
Windows PKI blog
Implementing LDAPS (LDAP over SSL)
Posted
over 2 years ago
by
Kurt L Hudson MSFT
2
Comments
LDAP over SSL (LDAPS) is becoming an increasingly hot topic - perhaps it is because Event Viewer ID 1220 is catching people's attention in the Directory Service Log or just that people are wanting the client to server LDAP communication encrypted. The...
Windows PKI blog
Deployment of the new Federal Common Policy CA Root Certificate
Posted
over 2 years ago
by
MS2065 [MSFT]
5
Comments
Background On December 1, 2010 the Federal PKI Management Authority (FPKIMA), in compliance with NIST guidance , created a new SHA-256 Federal Common Policy root certification authority. Windows Update will include the new Federal Common Policy Root...
Windows PKI blog
CA manager approval required for certificate re-enrollment
Posted
over 2 years ago
by
Fabian Müller [MSFT]
2
Comments
Hi there, this is Larry, Developer from US, and Fabian, PFE from Germany, writing about an uncommon scenario that might raise questions sometimes. When enrolling certificates to clients or users, you might want to have control regarding the initial...
Windows PKI blog
Quick Check on ADCS Health Using Enterprise PKI Tool (PKIVIEW)
Posted
over 2 years ago
by
Amerk [MSFT]
5
Comments
PKIVIEW was first introduced in Windows Server 2003 Resource kit. The tool is installed by default when you install the Windows 2008 Active Directory Certificate Services Role, and had been re-branded as "Enterprise PKI". The tool is implemented as a...
Windows PKI blog
Verifying The SSL Certificate Expiration with a tool
Posted
over 2 years ago
by
MS2065 [MSFT]
5
Comments
An active member of our community developed a very handy tool to verify - or let's actually say monitor - the validity of SSL server certificates. After downloading and extracting the the ZIP-file the tool is quite self explanatory. Press CTRL+A or click...
Windows PKI blog
Common Questions about SHA2 and Windows
Posted
over 2 years ago
by
Adam Stasiniewicz
4
Comments
Since my last post about SHA2 and Windows I’ve received numerous questions from customers and partners around three particular scenarios. This post will try to address those questions. Windows XP/2003 Enrollment in SHA2 Signed Certificates...
Windows PKI blog
SHA2 and Windows
Posted
over 3 years ago
by
MS2065 [MSFT]
15
Comments
UPDATE (2/8): Based on some recent questions, additional information has been posted about SHA2 and Windows. Introduction We’ve recently received a couple of requests from customers around the functionality of SHA-256 when running on Windows...
Windows PKI blog
Active Directory Certificate Services Monitoring Management Pack
Posted
over 3 years ago
by
MS2065 [MSFT]
0
Comments
A new version of the Certificate Services Monitoring Management Pack became available. Get more information from the Management Pack Catalog or the Microsoft Download Center .
Windows PKI blog
Microsoft Certificate Server virtualization policy
Posted
over 3 years ago
by
MS2065 [MSFT]
1
Comments
If you are unsure regarding the Microsoft Certificate server virtualization policy, just see the Microsoft Virtual Server support policy knowledgebase article at http://support.microsoft.com/kb/897613 . It is worth to mention that a hardware security...
Windows PKI blog
Backing up Windows Server 2008 ADCS CA Keys
Posted
over 3 years ago
by
markbcooper
6
Comments
[EDIT 2/20/2012] This problem has recently been resovled in a hotfix update. S ystem state backup does not include CA private keys in Windows Server 2008 or in Windows Server 2008 R2 - http://support.microsoft.com/kb/2603469 Backing up a Windows...
Windows PKI blog
Firewall Rules for Active Directory Certificate Services
Posted
over 3 years ago
by
oshekel
11
Comments
Below is a list of ports that need to be opened on Active Directory Certificate Services servers to enable HTTP and DCOM based enrollment The information was developed by Microsoft Consultant Services during one of our customer engagements ...
Windows PKI blog
Design Considerations before Building a Two Tier PKI Infrastructure
Posted
over 3 years ago
by
Amerk [MSFT]
6
Comments
Environmental Dependencies: 1- Determine if the Active Directory Forest has Windows 2000 Domain Controllers. This is important because of modifications to the CertPublishers group scope, and permissions related to the AdminSDHolder role. These permissions...
Windows PKI blog
Certificate Path Validation in Bridge CA and Cross-Certification Environments
Posted
over 3 years ago
by
siadukia
5
Comments
Recently, we’ve had a deluge of questions regarding chain building and selection, especially in the presence of cross-certified certificates. Hopefully, this post will make Crypto API 2 (CAPI2) chaining logic clearer and help enterprise admins design and troubleshoot their public key infrastructure....
Windows PKI blog
Powershell CRL Copy
Posted
over 3 years ago
by
MS2065 [MSFT]
7
Comments
This script writes a Certification Authority's Certificate Revocation List to HTTP based CRL Distribution Points via a UNC path. It checks to make sure that the copy was successful and that the CDPs have not and are not about to expire. Alerts/status...
Windows PKI blog
How to Request a Certificate With a Custom Subject Alternative Name
Posted
over 3 years ago
by
Alex Radutskiy [MSFT]
0
Comments
Today many servers require some sort of SSL certificate to be deployed and in many cases custom names are involved. My colleague just published a document How to Request a Certificate With a Custom Subject Alternative Name that I strongly recommend reading...
Windows PKI blog
Disaster Recovery Procedures for Active Directory Certificate Services (ADCS)
Posted
over 3 years ago
by
Amerk [MSFT]
20
Comments
Introduction: When designing a public key infrastructure (PKI) for your organization, you must develop an effective disaster recovery plan to ensure that, in the event of failure of the computer hosting Certificate Services, you can recover in a timely...
Windows PKI blog
Windows Server 2008 R2 AD CS Migration Guide
Posted
over 3 years ago
by
ltalbot
3
Comments
The official version of the new 2008 R2 ADCS Migration Guide is now available at http://technet.microsoft.com/en-us/library/ee126170(WS.10).aspx . The guide describes the necessary steps for a successful migration of both enterprise and standalone...
Windows PKI blog
What CA types are supported for clustering?
Posted
over 3 years ago
by
MS2065 [MSFT]
2
Comments
There are two types of certification authorities: Standalone and Enterprise. Only Enterprise certification authorities have been tested for clustered installations. A very short but may be important statement.
Page 2 of 5 (120 items)
1
2
3
4
5