<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://beta.blogs.microsoft.co.il/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Yuval Sinay : PKI</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx</link><description>Tags: PKI</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>How to renew User/Computer certificate without require to do application side changes</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2012/04/21/how-to-renew-user-computer-certificate-without-require-to-do-application-side-changes.aspx</link><pubDate>Sat, 21 Apr 2012 23:58:02 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:1071426</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=1071426</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2012/04/21/how-to-renew-user-computer-certificate-without-require-to-do-application-side-changes.aspx#comments</comments><description>&lt;p&gt;The renewal process of user/computer certificate require (in the most of the cases) to implemented changes in the application side (e.g. IIS,Outlook etc.),&lt;/p&gt; &lt;p&gt;As a workaround for this “limitation”, the renewal process of the User/computer certificate can be set to use exiting certificate key. &lt;/p&gt; &lt;p&gt;However, using exiting certificate key may reduce the system security level, and this may lead to system/certificate compromise.&lt;/p&gt; &lt;p&gt;Warring: To reduce the security risk of implementing changes in the Enterprise PKI (Public Key Infrastructure), its highly recommended to test this changes in a lab - before making changes in the production environment. &lt;/p&gt; &lt;p&gt;To renew the certificate by using exiting certificate key, please use the following instructions:&lt;/p&gt; &lt;p&gt;A. &lt;strong&gt;PKI Prerequisites&lt;/strong&gt;:&lt;/p&gt; &lt;p&gt;1. Depending on the certificate template type/settings, the Certificate Authority security settings should allow the user that renew the certificate to have the following privilege: “Request Certificates”.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/image_75A154FE.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://blogs.microsoft.co.il/blogs/yuval14/image_thumb_01569C31.png" width="269" height="351" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2. Depending on the certificate template type/settings, the user that renew the certificate may require the following privilege on the relevant Certificate Template: “Enroll” and/or “Autoenroll”.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/image_11163135.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://blogs.microsoft.co.il/blogs/yuval14/image_thumb_0EF9326C.png" width="280" height="360" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;B. &lt;strong&gt;The renewal process&lt;/strong&gt;:&lt;/p&gt; &lt;p&gt;1. Logon to the computer.&lt;/p&gt; &lt;p&gt;2. Navigate to “&lt;em&gt;Start&lt;/em&gt;” –&amp;gt; “Run” and type “mmc” and click “&lt;em&gt;OK&lt;/em&gt;” to launch the Management Console&amp;nbsp; &lt;/p&gt; &lt;p&gt;3. Navigate to “&lt;em&gt;File&lt;/em&gt;” &amp;gt; “&lt;em&gt;Add/Remove&lt;/em&gt;” Snap In… , select “&lt;em&gt;Certificates&lt;/em&gt;” and click “&lt;em&gt;Add&lt;/em&gt;”.&lt;/p&gt; &lt;p&gt;4. Select “&lt;em&gt;Computer Account&lt;/em&gt;” (or “&lt;em&gt;User Account&lt;/em&gt;”) and click “Next”. Then&amp;quot;, click “&lt;em&gt;Finish&lt;/em&gt;”. Once back on the Snap In screen, click “OK”.&lt;/p&gt; &lt;p&gt;5. Expand “&lt;em&gt;Certificates&lt;/em&gt;” &amp;gt; “&lt;em&gt;Personal&lt;/em&gt;” and click on “&lt;em&gt;Certificates&lt;/em&gt;”.&lt;/p&gt; &lt;p&gt;6. Right-click on the required certificate and select “&lt;em&gt;All Tasks&lt;/em&gt;” &amp;gt; “&lt;em&gt;Advanced Operations&lt;/em&gt;” &amp;gt; “&lt;em&gt;Renew This Certificate with the Same Key&lt;/em&gt;”.&lt;/p&gt; &lt;p&gt;7. Click “&lt;em&gt;Next&lt;/em&gt;”, and then “&lt;em&gt;Enroll&lt;/em&gt;”. Once complete, click “&lt;em&gt;Finish&lt;/em&gt;”.&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=1071426" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Certificate/default.aspx">Certificate</category></item><item><title>Monitoring Workgroup computers by using SCE 2010</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/10/07/monitoring-workgroup-computers-by-using-sce-2010.aspx</link><pubDate>Fri, 07 Oct 2011 05:35:29 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:911637</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=911637</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/10/07/monitoring-workgroup-computers-by-using-sce-2010.aspx#comments</comments><description>&lt;p&gt;Microsoft SCE 2010 is a light edition of Microsoft System Center products line. Monitoring Workgroup computers by using SCE 2010 is cover by the following Microsoft post:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc339464.aspx"&gt;How to Prepare the Essentials Management Server to Manage Workgroup-Joined Computers&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;However, you may found out that no information is available on the correct process to create a server certificate (that used for mutual authentication).&lt;/p&gt;  &lt;p&gt;The following Microsoft post cover the process how to create a server certificate.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/947691"&gt;When you try to install a System Center Operations Manager 2007 agent on a workgroup computer without using a gateway server, Operations Manager 2007 cannot see the workgroup computer&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Note1: The SCE 2010 Agent Installation wizard should be used for importing the following certificates:&lt;/p&gt;  &lt;p&gt;1. Trusted Root Certificate Authority.&lt;/p&gt;  &lt;p&gt;2. WSUS certificates.&lt;/p&gt;  &lt;p&gt;3. Server certificate of the workgroup computer.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/WorkgroupAgent_Installation_40647E4B.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="WorkgroupAgent_Installation" border="0" alt="WorkgroupAgent_Installation" src="http://blogs.microsoft.co.il/blogs/yuval14/WorkgroupAgent_Installation_thumb_693F6D87.png" width="423" height="240" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note2:To assign exiting certificate to the SCE 2010 agent, please use the utility: “MOMCertImport” (from SCE 2010/SCOM 2007/2007 R2 media) – after completing the Agent installation.&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=911637" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Microsoft+System+Center/default.aspx">Microsoft System Center</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/SCE+2010/default.aspx">SCE 2010</category></item><item><title>How to resolve Exchange 2010 error message: The Certificate Status could not be determined because the revocation check failed</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/20/how-to-resolve-exchange-2010-error-message-the-certificate-status-could-not-be-determined-because-the-revocation-check-failed.aspx</link><pubDate>Tue, 20 Sep 2011 21:31:31 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:903375</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=903375</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/20/how-to-resolve-exchange-2010-error-message-the-certificate-status-could-not-be-determined-because-the-revocation-check-failed.aspx#comments</comments><description>&lt;p&gt;The following error/s may appear in the Exchange 2010 Management Console:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;Exchange 2010 Certificate Revocation Checks and Proxy Settings&lt;/em&gt;” or “&lt;em&gt;The Certificate Status could not be determined because the revocation check failed&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Cause:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;1. You may use a Proxy server that block access to the CRL.&lt;/p&gt; &lt;p&gt;2. The CRL isn&amp;#39;t available.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;How to Debug this issue:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Obtain any (current) certificate from the Certificate Authority and run the following command:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;certutil –verify –urlfetch C:\CertificateName.cer &amp;gt;Log.txt&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;Usually you may find out issues like errors messages on expired CRL or Offline CA.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Resolutions:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;1. Review Proxy settings by using “&lt;em&gt;netsh winhttp show proxy&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;You can reset the proxy settings by using the commands:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;netsh winhttp reset proxy&lt;/em&gt;”&lt;br /&gt;”&lt;em&gt;netsh winhttp reset tracing&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;Note: You can also add Proxy exceptions (e.g. The CRL location) by using the following commands:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;netsh winhttp import proxy ie&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;“&lt;em&gt;netsh winhttp set proxy proxy-server=&lt;/em&gt;&lt;a href="http://192.168.1.1:80"&gt;&lt;em&gt;http://192.168.1.1:80&lt;/em&gt;&lt;/a&gt;&lt;em&gt; bypass-list=&amp;quot;crlserver.DomainName.local&lt;/em&gt;&amp;quot;&lt;/p&gt; &lt;p&gt;“&lt;em&gt;netsh winhttp set proxy proxy-server=&lt;/em&gt;&lt;a href="http://192.168.1.1:4"&gt;&lt;em&gt;http://192.168.1.1:4&lt;/em&gt;&lt;/a&gt;&lt;em&gt;43 bypass-list=&amp;quot;crlserver.DomainName.local&lt;/em&gt;&amp;quot;&lt;/p&gt; &lt;p&gt;2. Review the current CRL settings in the Active Directory by using:&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/b/pki/archive/2011/02/28/quick-check-on-adcs-health-using-enterprise-pki-tool-pkiview.aspx"&gt;Quick Check on ADCS Health Using Enterprise PKI Tool (PKIVIEW)&lt;/a&gt;&lt;br /&gt;&lt;/p&gt; &lt;p&gt;Usually, if you are using a Offline CA (Root CA for example), you may find out that the current CRL was expired.&lt;/p&gt; &lt;p&gt;Usually its recommended to change the CRL expire date in the relevant CA and then re-publish the CRL.&lt;/p&gt; &lt;p&gt;Then, import the CRL into the Active Directory by using the command:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;certutil -f -dspublish CRLFileName.crl&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;3. If the CRL is published to a File Share and/or Web Server (HTTP/s), please verify that the URL paths exits and aren&amp;#39;t blocked by third party system (e.g. Firewall, Antivirus, IPS etc.) Its also recommended to verify that no NTFS/Share permissions blocked access to the CRL.&lt;/p&gt; &lt;p&gt;4. Reset urlcache by using the following power shell commands:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;certutil -urlcache ocsp delete&lt;/em&gt;”&lt;br /&gt;”&lt;em&gt;certutil -urlcache crl delete&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;5. Reset the Exchange Internet Web Proxy to null by using the following power shell command:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;Set-ExchangeServer&amp;nbsp; -InternetWebProxy $NULL&lt;/em&gt;”&lt;/p&gt; &lt;p&gt;6. Delete MMC cache files from:&lt;/p&gt; &lt;p&gt;“&lt;em&gt;C:\Users\%username%\AppData\Roaming\Microsoft\MMC&lt;/em&gt;” &lt;p&gt;7. Verify that CRL for Root &amp;amp; SubCA URL’s/Paths are current. Also, &lt;/p&gt; &lt;p&gt;8. Verify that the Root CA Certificate was added to the computer Trusted Root CA Store.&lt;/p&gt; &lt;p&gt;Also, verify that the SubCA Certificate was added to the computer Intermediate CA Store.&lt;/p&gt; &lt;p&gt;9. As a temporary workaround, you can enable the required certificate by using Exchange Power Shell command: &lt;a href="http://technet.microsoft.com/en-us/library/aa997231.aspx"&gt;Enable-ExchangeCertificate&lt;/a&gt;&lt;/p&gt; &lt;p&gt;However, this workaround wouldn’t resolved the error message, but would enable you to assign the certificate to the Exchange services.&lt;/p&gt; &lt;p&gt;For farther information, please review: &lt;a href="http://technet.microsoft.com/en-us/library/bb457027.aspx"&gt;Certificate Revocation and Status Checking&lt;/a&gt;&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=903375" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Exchange+2010/default.aspx">Exchange 2010</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Digital+Certificate/default.aspx">Digital Certificate</category></item><item><title>How to Publish Root Certificate and Intermediate Root Certificate in Active Directory</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/14/how-to-publish-root-certificate-and-intermediate-root-certificate-in-active-directory.aspx</link><pubDate>Wed, 14 Sep 2011 04:10:17 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:900337</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=900337</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/14/how-to-publish-root-certificate-and-intermediate-root-certificate-in-active-directory.aspx#comments</comments><description>&lt;p&gt;To Publish Root Certificate and Intermediate Root Certificate in Active Directory, please use the following commands:&lt;/p&gt;  &lt;p&gt;Root certificate: certutil -dspublish -f RootCACertificate.crt RootCA&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Intermediate certificate: certutil -dspublish -f SubCACertificate.crt SubCA&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;To publish the certificate/s to NTAuth store, please review the following knowledgebase:&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/295663"&gt;How to import third-party certification authority (CA) certificates into the Enterprise NTAuth store&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note: NTAuth store point to: CN=NTAuthCertificates,CN=Public Key Services,CN=Services,CN=Configuration,DC=MyDomain,DC=com&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=900337" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category></item><item><title>How to add Root Certificate and Intermediate Certificate to a Windows Operating System</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/13/how-to-add-root-certificate-and-intermediate-certificate-to-a-windows-operating-system.aspx</link><pubDate>Wed, 14 Sep 2011 03:46:04 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:900246</guid><dc:creator>yuval14</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=900246</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/13/how-to-add-root-certificate-and-intermediate-certificate-to-a-windows-operating-system.aspx#comments</comments><description>&lt;p&gt;If you are using a PKI (Public Key Infrastructure), you may found out that Root Certificate and Intermediate Certificate may need be installed manually for Workgroup computers.&lt;/p&gt;  &lt;p&gt;Also, in case that you don’t use Active Directory (e.g. GPO etc.) to publish the Root Certificate and Intermediate Certificate details, you may need to add this certificates manually.&lt;/p&gt;  &lt;p&gt;To accomplish this task, please use the following commands:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Installing Root Certificate: “&lt;em&gt;Certutil -addstore -f Root MyRootCACertificate.crt&lt;/em&gt;”&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Installing Intermediate Certificate: “&lt;em&gt;Certutil -addstore -f CA MySubCACertificate.crt&lt;/em&gt;”&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;You can use the following commands to review the result of the previous commands:&lt;/p&gt;  &lt;p&gt;“&lt;em&gt;certutil -v –store my &amp;gt; LocalCertStore.txt&lt;/em&gt;“ or “&lt;em&gt;certutil –verifystore root&lt;/em&gt;” /&amp;#160; “&lt;em&gt;certutil –verifystore CA&lt;/em&gt;”&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=900246" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category></item><item><title>Finding DSConfigDN and DSDomainDN values by using Certutil</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/01/finding-dsconfigdn-and-dsdomaindn-values-by-using-certutil.aspx</link><pubDate>Thu, 01 Sep 2011 05:55:03 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:891484</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=891484</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/01/finding-dsconfigdn-and-dsdomaindn-values-by-using-certutil.aspx#comments</comments><description>&lt;p&gt;DSConfigDN and DSDomainDN are two objects that should be taken care while designing PKI implementation (specially in case&amp;#160; of using a Stand Alone Root CA and a Enterprise Sub CA).&lt;/p&gt;  &lt;p&gt;The following output provides you instructions how to obtain the required values from your Certificate Authority:&lt;/p&gt;  &lt;p&gt;C:\Users\administrator&amp;gt;certutil -getreg&amp;#160; ca\DSConfigDN&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\lyncd    &lt;br /&gt;omain-SRV5-CA\DSConfigDN:&lt;/p&gt;  &lt;p&gt;&amp;#160; DSConfigDN REG_SZ = &lt;strong&gt;CN=Configuration,DC=lyncdomain,DC=local&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;CertUtil: -getreg command completed successfully.&lt;/p&gt;  &lt;p&gt;C:\Users\administrator&amp;gt;certutil -getreg&amp;#160; ca\DSDomainDN   &lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\lyncd    &lt;br /&gt;omain-SRV5-CA\DSDomainDN:&lt;/p&gt;  &lt;p&gt;&amp;#160; DSDomainDN REG_SZ = &lt;strong&gt;DC=lyncdomain,DC=local     &lt;br /&gt;&lt;/strong&gt;CertUtil: -getreg command completed successfully.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note: A Stand Alone Root CA / Stand Alone Sub CA details (e.g. Certificate, CRL, AIA etc.) could be published into the Active Directory by using the following commands:&lt;/p&gt;  &lt;p&gt;“CertUtil -dsPublish -f RootCACertificate.cer RootCA “&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;“CertUtil -dsPublish -f SubCACertificate.cer SubCA “&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/image_19C47634.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://blogs.microsoft.co.il/blogs/yuval14/image_thumb_26227390.png" width="385" height="263" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/image_239941D2.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://blogs.microsoft.co.il/blogs/yuval14/image_thumb_2E76231A.png" width="377" height="236" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;To publish CRL into the Active Directory you should use the following command:&lt;/p&gt;  &lt;p&gt;“&lt;em&gt;certutil -dspublish-f&amp;#160; MyCRLFile.Crl&lt;/em&gt; “&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/image_474D93C6.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://blogs.microsoft.co.il/blogs/yuval14/image_thumb_640708DB.png" width="370" height="256" /&gt;&lt;/a&gt;    &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;Reference:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc737740(WS.10).aspx"&gt;Configure an offline root certification authority to support certificate revocation with Active Directory&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/295663"&gt;How to import third-party certification authority (CA) certificates into the Enterprise NTAuth store&lt;/a&gt;&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=891484" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category></item><item><title>Windows 2008 R2 Certification Authority installation guide</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/08/11/windows-2008-r2-certification-authority-installation-guide.aspx</link><pubDate>Fri, 12 Aug 2011 03:18:47 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:883149</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=883149</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/08/11/windows-2008-r2-certification-authority-installation-guide.aspx#comments</comments><description>&lt;p&gt;Mr. Eyal Estrin wrote an excellent guide on “&lt;em&gt;Windows 2008 R2 Certification Authority installation guide&lt;/em&gt;”.&lt;/p&gt;  &lt;p&gt;This guide provides a step by step guide how to install a Offline Root Certificate Authority and then setup a Enterprise Subordinate Certificate Authority.&lt;/p&gt;  &lt;p&gt;The guide can be obtain from the following &lt;a href="http://security-24-7.com/windows-2008-r2-certification-authority-installation-guide/"&gt;link&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=883149" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Security/default.aspx">Security</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Security+Guides/default.aspx">Security Guides</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category></item><item><title>Error “Page Cannot be Displayed” may appear after replacing Exchange 2010 Certificate</title><link>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/07/03/error-page-cannot-be-displayed-may-appear-after-replacing-exchange-2010-certificate.aspx</link><pubDate>Mon, 04 Jul 2011 00:19:53 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:849113</guid><dc:creator>yuval14</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://beta.blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=849113</wfw:commentRss><comments>http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/2011/07/03/error-page-cannot-be-displayed-may-appear-after-replacing-exchange-2010-certificate.aspx#comments</comments><description>&lt;p&gt;Symptoms:&lt;/p&gt;  &lt;p&gt;After replacing Exchange 2010 Certificate , the following error may appear during accessing Exchange 2010 OWA (Outlook Web Access): “&lt;em&gt;Page Cannot be Displayed&lt;/em&gt;”.&lt;/p&gt;  &lt;p&gt;Reason:&lt;/p&gt;  &lt;p&gt;The imported certificate may not contain a “Private key”.&lt;/p&gt;  &lt;p&gt;Solution:&lt;/p&gt;  &lt;p&gt;During certificate export process, verify that “Export Private Key” checkbox has been marked. After completing the new certificate, import it the Exchange 2010 server and assigned it to the relevant services.&lt;/p&gt;&lt;img src="http://beta.blogs.microsoft.co.il/aggbug.aspx?PostID=849113" width="1" height="1"&gt;</description><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Exchange+2010/default.aspx">Exchange 2010</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/PKI/default.aspx">PKI</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/SSL/default.aspx">SSL</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Public+Key+Infrastructure/default.aspx">Public Key Infrastructure</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/OWA/default.aspx">OWA</category><category domain="http://beta.blogs.microsoft.co.il/blogs/yuval14/archive/tags/Outlook+Web+Access/default.aspx">Outlook Web Access</category></item></channel></rss>