Sign in
Windows PKI blog
News and information for public key infrastructure (PKI) and Active Directory Certificate Services (AD CS) professionals
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
A Certificate could not be created
Active Directory Domain Services
AD CS
AD CS documentation updates
architecture
Backup Private Keys ADCS 2008 R2 p12 CA
CA
CA maintenance
certificate
certificate requests
certificates
Certification authority
certifiication authority
certutil
Configuration
CRL
cryptography
Data Recvoery
Homeland Security Presidential Directive 12
HSPD-12
key management
PKI
setup
SHA2 NIST SP800-78-2 SP800-57
whitepaper
Archive
Archives
May 2013
(1)
March 2013
(3)
December 2012
(3)
October 2012
(1)
August 2012
(1)
July 2012
(1)
June 2012
(3)
May 2012
(2)
April 2012
(2)
March 2012
(2)
February 2012
(1)
January 2012
(2)
December 2011
(1)
October 2011
(3)
September 2011
(2)
August 2011
(3)
June 2011
(2)
March 2011
(2)
February 2011
(3)
September 2010
(1)
August 2010
(3)
June 2010
(2)
May 2010
(2)
April 2010
(2)
March 2010
(2)
February 2010
(1)
January 2010
(2)
December 2009
(2)
November 2009
(2)
October 2009
(2)
September 2009
(7)
August 2009
(10)
July 2009
(1)
June 2009
(2)
May 2009
(2)
April 2009
(2)
February 2009
(1)
January 2009
(4)
December 2008
(2)
October 2008
(3)
September 2008
(1)
July 2008
(1)
June 2008
(1)
May 2008
(1)
April 2008
(1)
February 2008
(2)
January 2008
(1)
November 2007
(1)
October 2007
(1)
September 2007
(1)
August 2007
(2)
July 2007
(2)
May 2007
(2)
April 2007
(1)
February 2007
(4)
January 2007
(1)
December 2006
(3)
November 2006
(1)
TechNet Blogs
>
Windows PKI blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows PKI blog
How to create a web server SSL certificate manually
Posted
over 4 years ago
by
MS2065 [MSFT]
12
Comments
The Internet Information Server (IIS) and Microsoft Internet Security and Acceleration (ISA) provide wizards in the administration user interface to request and install SSL certificates. With this blog post I want to explain how to request a SSL server...
Windows PKI blog
Morello on PKI
Posted
over 4 years ago
by
MS2065 [MSFT]
0
Comments
I came across two valuable blog posts from my co-worker Morello. The articles have been posted to the Windows Server Customer engineering blog – check them out! CRL freshness checking scripts To Cluster or Not to Cluster CAs
Windows PKI blog
What is a strong key protection in Windows?
Posted
over 4 years ago
by
Alex Radutskiy [MSFT]
15
Comments
Strong key protection is one of the most misunderstood features in Windows security. In this post I will attempt to demystify it. I will also try to address some of the misconceptions about this feature that I’ve come across on the security discussion...
Windows PKI blog
PKI Enhancements in Windows 7 and Windows Server 2008 R2
Posted
over 4 years ago
by
MS2065 [MSFT]
1
Comments
The TechNet Magazine released a new article about the PKI Enhancements in Windows 7 and Windows Server 2008 R2 in the May 2009 issue.
Windows PKI blog
CA performance
Posted
over 4 years ago
by
MS2065 [MSFT]
0
Comments
Back in the year 2003 we have published information about the CA performance and how it is impacted by various factors. The TechNet article is called Evaluating CA Capacity, Performance, and Scalability and is more or less still valid. You may transform...
Windows PKI blog
PKI at TechEd 2009 in LA
Posted
over 4 years ago
by
cmaca
1
Comments
Attending TechEd 2009 next week? If you or your customers are around on Monday 5/11, I (objectively) recommend attendance at the “ PKI in a Web Services World ” breakout session from 2:45-4PM in room 408A. This session is our first public breakout for...
Windows PKI blog
How to configure the Windows Server 2008 CA Web Enrollment Proxy
Posted
over 4 years ago
by
MS2065 [MSFT]
0
Comments
A co-worker posted an interesting blog about configuring the Windows Server 2008 CA Web Enrollment proxy at http://blogs.technet.com/askds/archive/2009/04/22/how-to-configure-the-windows-server-2008-ca-web-enrollment-proxy.aspx .
Windows PKI blog
Suite B PKI in Windows Server 2008 and Windows Server 2008R2
Posted
over 4 years ago
by
ltalbot
1
Comments
I'm happy to announce the availability of the Suite B PKI in Windows Server 2008 whitepaper. The paper was written to provide information that could benefit those looking to implement strict Suite B cryptographic functionality within their own PKI deployments...
Windows PKI blog
Certificate distribution and the Microsoft Terminal Services Client
Posted
over 4 years ago
by
MS2065 [MSFT]
0
Comments
A few days ago I worked in a test environment that also consists of a PKI. I used the Microsoft Terminal Services Client (mstsc.msc) for a while to connect to various machines in the test environment. One day, I helped a coworker troubleshooting a certificate...
Windows PKI blog
Certificate Services setup failed with the following error: Element not found. 0x80070490
Posted
over 4 years ago
by
MS2065 [MSFT]
2
Comments
Until Windows Server 2008 shipped, every Domain Controller had a readable and writable copy of the Active Directory schema, domain naming context and configuration naming context. This statement changed when we introduced the Read Only Domain Controller...
Windows PKI blog
Cross-forest Certificate Enrollment with Windows Server 2008 R2 Beta
Posted
over 4 years ago
by
MS2065 [MSFT]
1
Comments
I am excited to announce the public availability of the Cross-forest Certificate Enrollment with Windows Server 2008 R2 whitepaper. The product team worked hard to make this breakthrough functionality happen in Windows Server 2008 R2 . Now is the time...
Windows PKI blog
How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003
Posted
over 4 years ago
by
MS2065 [MSFT]
1
Comments
Today I want to comment on the quite popular Microsoft Knowledgebase article How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003 and from Windows 2000 Server . I am referring...
Windows PKI blog
New Windows Biometric Framework and Driver Model
Posted
over 4 years ago
by
MS2065 [MSFT]
0
Comments
Those of you who are interested in biometrics should look at the following documents: Introduction to the Windows Biometric Framework (WBF) New Windows Biometric Framework and Driver Model Windows 7 Beta WDK
Windows PKI blog
Outlook S/MIME certificate selection
Posted
over 5 years ago
by
MS2065 [MSFT]
4
Comments
Consider that you are sending an encrypted eMail to a recipient who has multiple certificates stored in Active Directory. The key question is: Which certificates are selected by Outlook 2003/2007? When sending an encrypted eMail, Outlook actually requires...
Windows PKI blog
Defining the friendly name certificate property
Posted
over 5 years ago
by
MS2065 [MSFT]
2
Comments
The friendly name of a certificate can be helpful if multiple certificates with a similar subject exist in a certificate store. One way to set the friendly name is through the certificate MMC SnapIn. Alternatively certutil.exe can be used in the following...
Windows PKI blog
Suppressing certificate attributes in a CA certificate request
Posted
over 5 years ago
by
MS2065 [MSFT]
0
Comments
When a PKCS#10 request for a CA certificate is generated, a pre-defined set of certificate attributes is included. This blog entry explains how to eliminate attributes that would go into the CA certificate request by default. Imagine that you are setting...
Windows PKI blog
Creating offline certificate requests through the user-interface on Windows Vista or Windows Server 2008
Posted
over 5 years ago
by
MS2065 [MSFT]
0
Comments
Windows Vista and Windows Server 2008 have a convenient user interface to create custom certificate requests. This is especially helpful since computer certificate enrollment through the web enrollment pages was discontinued from Windows Server 2008 and...
Windows PKI blog
Disposition values for certutil –view –restrict (and some creative samples)
Posted
over 5 years ago
by
MS2065 [MSFT]
1
Comments
A while ago I explained how to determine all certificates that will expire within a given period. Now I’d like to explain how to query the CA database based on certificate or request disposition. The disposition ID’s are defined in the certsrv.h include...
Windows PKI blog
TechNet Presents: MCS Talks Enterprise Architecture session 4 – Security and PKI
Posted
over 5 years ago
by
MS2065 [MSFT]
0
Comments
You may be interested in one of our upcoming sessions that is focused on PKI design and is available for registration here: http://blogs.technet.com/mcstalks/archive/2008/09/02/session-4-details-security-and-pki-registration-now-available.aspx
Windows PKI blog
You cannot add V2 or V3 templates after an inplace upgrade was performed on a Windows Server 2008 enterprise CA
Posted
over 5 years ago
by
MS2065 [MSFT]
2
Comments
Technically, it is possible to install an enterprise CA on a Windows Server Standard edition. With this configuration, enterprise features of the certification authority are intentionally not available. To enable the CA enterprise features, it is required...
Windows PKI blog
How EffectiveDate (thisupdate), NextUpdate and NextCRLPublish are calculated
Posted
over 5 years ago
by
MS2065 [MSFT]
4
Comments
The validity time of a certificate revocation list (CRL) is critical for every public key infrastructure. By default, most applications verify the validity of certificates against a CRL. Two CRL types exist: base CRLs and delta CRLs. In case where...
Windows PKI blog
New whitepapers about Windows Server 2008 Certificate Services
Posted
over 5 years ago
by
MS2065 [MSFT]
1
Comments
This blog-entry has two purposes: 1) make you aware of the two new whitepapers that have been just released: Active Directory Certificate Services Upgrade and Migration Guide Configuring and Troubleshooting Certification Authority Clustering in Windows...
Windows PKI blog
How to determine all certificates that will expire within 30 days
Posted
over 5 years ago
by
MS2065 [MSFT]
3
Comments
Woudn't it be interesting for the CA admin to know which certificates are expiring in the near future? If autoenrollment is not eanbled, certificate users should be informed in advance before they actually loose functionality. A simple certutil command...
Windows PKI blog
How to avoid Delta CRL download errors on Windows Server 2008 with IIS7
Posted
over 5 years ago
by
MS2065 [MSFT]
0
Comments
If delta CRLs are hosted on a Windows Server 2008 server running Internet Information Server 7 (II7), the configuration of a request filter must be changed in the IIS7 configuration. IIS7.0 does not allow URI’s that do not match upon double escaping...
Windows PKI blog
Update: Import the Root CA Certificate and CRL into an Intermediate CA from a Batch File
Posted
over 5 years ago
by
MS2065 [MSFT]
0
Comments
It came to our attention that the Best Practices for Implementing a Microsoft Windows Server 2003 Public Key Infrastructure whitepaper provides wrong guidance in section Import the Root CA Certificate and CRL into an Intermediate CA from a Batch File...
Page 4 of 5 (120 items)
1
2
3
4
5