Certificate Authority does it have to be on a Domain Controller
I'm trying to setup "Certification Authority" on a Windows 2008 server and I'm not have any success. I have a wildcard certificate from godaddy, so it is *.domainname.com and I don't know if windows is having problems with that or not?I made my original request from an linux apache box and then using openssl I converted the certificate from PEM or filename.crt to a .pfx file. I can import the file, but when I click next I get the following message: The selected certificate could not be used. I was wondering if it was because of the wildcard certificate or because my windows 2008 server is not a domain controller?I would appreciate any help with this. I'd like to setup NPS and IAS, but I need the certificate working first.jviola
March 26th, 2009 9:44pm

Hi, This issue may not be caused by wildcard certificate or not being a DC. It may be caused by incorrect certificate type. If you can setup the CA and get the error when configure NPS and IAS server, please try the suggestions below for troubleshooting. NPS and IAS Server needs certificates which was based on "RAS and IAS Server template". If the wildcard certificates is not "RAS and IAS Server" certificate, the error "The selected certificate could not be used" may occur. Please try to get a certificates based on "RAS and IAS Server template" to test. You can also try to configure your own CA to deploy certificates. For detailed steps, please refer to the following article. Deploy a CA and NPS Server Certificate http://technet.microsoft.com/en-us/library/cc730811.aspx NPS Server Certificate: Configure the Template and Autoenrollment http://technet.microsoft.com/en-us/library/cc754198.aspx If the error was received when installing the CA, please help to collect the following information for research. 1. At which step did you receive the error message? Please describe your steps in detail. 2. You mentioned that you had a wildcard certificate. Where is this certificate used? Is this the certificate that you converted by using openssl and failed to import? 3. Please collect the C:\Windows\Logs\ServerManager.log if the Certificate Authority role is not installed properly. Thanks. This posting is provided "AS IS" with no warranties, and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
March 30th, 2009 6:58am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics