Certificate Renewals
I've got two certificates installed on a production isa 2006 server servicing a couple of thousand users. I want to create renewal requests for them. When I go to export them as a backup, the option to export the privatekey is greyed out. When I go to the mmc and try and 'renew a certificate with the same key'I get the error: 'The selected certifcate has no private key. The smart card resourcemanager is not running. I tried starting the smart card service in windows services but that had no effect. Since this is an ISA server it doesn't have a website to try from. When I try 'renew a certifcate with a different key' I get: 'This certifcatecannot be renewed because it does not contain enough information to generate a renewal request. I don't know what server the original cert was created on. Is there any way round this or do I have to request a new certifcate. And should I request a new cert with the same key or a different one?
May 22nd, 2008 1:41pm

Hello, Private key can't be exported unless you specify "mark keys as exportable". And the permission on the certificate template determines whether you can mark key as exportable in the process of certificate request. You may check the certificate in the General tab whether you have a private key that corresponds to the certificate. This error message "This certificate cannot be renewed because it does not contain enough information to generate a renewal request" indicates that the certificate template did not require enough information from the user to properly submita renewal. You can have a try to renew the certificate via web enrollment page with PKCS. For your reference: Request Certificates http://technet2.microsoft.com/windowsserver/en/library/114e8b9c-6c93-462a-b176-dbd5f0b2db7c1033.mspx
Free Windows Admin Tool Kit Click here and download it now
June 6th, 2008 1:14pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics