burgemaster Posted November 19, 2014 Posted November 19, 2014 Hi All, We get our SSLs from the LEAs who act as a contact point for the school to get ahold of our certs. When we create the request it MUST have their address details in the request or it doesnt get approved when they request it with JANET. All my searching leads me down the wrong path.. All I am after is to create a request with multiple SANs with the LEAs details in it? We have Certsrv setup on our 2012 server. Can anyone please help? Thanks in advance
Dkeen94 Posted November 19, 2014 Posted November 19, 2014 Can you not ask the LEA to request a SAN Cert from JANET with the names that you specify. When we get ours we have a list of names that are already provided within the SAN
burgemaster Posted November 19, 2014 Author Posted November 19, 2014 Can you not ask the LEA to request a SAN Cert from JANET with the names that you specify. When we get ours we have a list of names that are already provided within the SAN Thanks Dkeen94, But wouldn't the cer have to be imported back in to where it was requested from? or are you saying that they could then export it with the private key or similar? I don't think ours will do this. They gave me the strict instructions on what we need in it and it has to be a .req request.
localzuk Posted November 19, 2014 Posted November 19, 2014 It depends what you're going to import the certificate into. If its, say, IIS7, then these instructions work: How to Request a Certificate With a Custom SAN 1
burgemaster Posted November 19, 2014 Author Posted November 19, 2014 It depends what you're going to import the certificate into. If its, say, IIS7, then these instructions work: How to Request a Certificate With a Custom SAN Thanks localzuk, I followed that guide and I ended up with a signed SAN on our CA. I need a request. I probably did it wrong but coLunt see where to export it after or enter the address of the lea.. The cert will be used on both our smoothwall box and our zone director as currently when devices connect they are getting a self signed cert that obviously isn't from a trusted source.
localzuk Posted November 19, 2014 Posted November 19, 2014 I think you've followed the wrong bit. The part you want to follow is from "Using Certificate Enrollment wizard with a standalone CA". That section will generate a CSR to use. You'll want to ensure that on step 10b you have the private keys marked as exportable - so they can be imported into other servers.
burgemaster Posted November 19, 2014 Author Posted November 19, 2014 hold fire... I was following the wrong section!! haha there's a wasted could of hours! Thanks Localzuk
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now