Hi,
We've been trying to enable SSL on our AD system. We followed procedure at:
http://support.microsoft.com/kb/321051
Prior to doing anything, we imported the CA and SubCA certs on the AD
machine using the MMC Certificates snap-in.
Then, we created the cert request using certreq, submitted the request
to the SubCA, and saved the server cert that the SubCA issued.
We got an error (don't remember what) when we tried to do the "certreq -
accept", so then we used the MMC Certificate snap-in to import the
server cert into Local Computer/Personal.
We restarted the AD machine, but even after that, when we test SSL using
ldp.exe, we cannot connect.
When we double-click on the server cert in MMC Certificate snap-in on
the AD machine, the server cert looks ok, so I'm puzzled by why the SSL
is still not working.
I did note that when we double-click on the cert, the text "You have a
private key that corresponds to this certificate" is *NOT* displayed,
and I also note that in the article above, one of the requirements is:
"A private key that matches the certificate is present in the Local
Computer's store and is correctly associated with the certificate.
The private key must not have strong private key protection
enabled."
So, I'm thinking that the problem is that we don't have the private key
associated with the server cert, but I don't know why not?
I thought that when we created the cert request using the certreq.exe,
that that would cause a private key to be created and stored, but we
must be doing something wrong.
Can anyone here tell me what step we missed and how we create/store the
private key that that article is talking about?
Thanks in advance,
Jim
Bookmarks