Certificate Store for IIS7 and auto-enrollment
Hi Folks, I am running IIS7 on Windows Server 2008r2 which is a also Certificate Authority, and in addition has a server identification certificate signed by the CA in his personal store which is configured with Subject Alternative Names. I have two problems: 1) From IIS Manager, I can select the server and look at "Server Certificates" in the IIS section. I see two. One is the CA and the other is a wrong server identification certificate that has been auto-generated. If I delete the server identification certificate, it magically re-appears. How do I stop this? 2) I have a server identification certificate already signed by the CA and I'd like that certificate to be used for server identification, but I see no way to import that certificate. How do I do this? Where is this store located, meaning, how can I see it using MMC - Certificates snap-in? The choices are User/Service/Machine accounts and various choices beyond that. I have fired up "Certificates" in MMC and selected on separate occasions both "Computer Account" and "Service Account (IIS Admin Service)" and even though these seemed like good guesses, they turn out to be wrong guesses.Thanks for the help, Chris.
August 16th, 2012 5:30pm

Using the certificate management MMC snap-in, select the Computer Account and local computer in the next step and when the snap-in loads look under personal in the left tree. This is where computer certificates used by services are located. The auto generated self-signed certificate that keeps getting back is probably the RDP service certificate. How was the "not showing" certificate generated, auto/manual enrollment or just imported in the system? /Hasain
Free Windows Admin Tool Kit Click here and download it now
August 16th, 2012 5:45pm

Using the certificate management MMC snap-in, select the Computer Account and local computer in the next step and when the snap-in loads look under personal in the left tree. This is where computer certificates used by services are located. The auto generated self-signed certificate that keeps getting back is probably the RDP service certificate. How was the "not showing" certificate generated, auto/manual enrollment or just imported in the system? /Hasain
August 16th, 2012 5:52pm

Hi Chris, We can also seek help in the IIS Forum. There you can get effective suggestion by other experts who familiar with this product. Your understanding is appreciated. Official IIS Forum http://forums.iis.net/ Regards Kevin
Free Windows Admin Tool Kit Click here and download it now
August 19th, 2012 11:42pm

Hi Chris, We can also seek help in the IIS Forum. There you can get effective suggestion by other experts who familiar with this product. Your understanding is appreciated. Official IIS Forum http://forums.iis.net/ Regards Kevin
August 19th, 2012 11:47pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics