IIS Server Security - RE: How to create a client side certificate on a Windows 2000 Serv

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > March 2005 > RE: How to create a client side certificate on a Windows 2000 Serv





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author RE: How to create a client side certificate on a Windows 2000 Serv
Abel Chan

2005-03-17, 5:55 pm

Hi WenJun,

I tried and I still getting the same "The specified client certificate
cannot be loaded" error".

Note: I have not sent the certificate to the remote web site. I should get
a different error (406) if I have correctly installed the correct certificate
on my local BTS machine.

To make sure I following all the steps correctly, I have:
1) Install CA on a 2003 box and provide a CN.
2) On the 2003 box, go to http://localhost/certsrv/default.asp and request a
Certificate.
3) On the BTS box, go to http://[2003boxservername]/certsrv/default.asp
4) There are four links under "Select a task:". I click on the link
"Download a CA certificate, certificate chain, or CRL"
5) Now I am on Download a CA Certificate, Certificate Chain, or CRL page.
It lists a certificate under "CA certificate:" and it is selected. The
Encoding method is DER. Under the Encoding method, there are four links:
Download CA certificate
Download CA certificate chain
Download latest base CRL
Download latest delta CRL.
6) I click on the link "Download CA certificate" and save it into a local
directory.
7) Launch mmc and add Certificate snap-in.
8) Go to console Root | Certificates | Personal | Certificates | All Tasks |
Import the saved certificate file.
9) Go to console Root | Certificates | Trusted Root certification |
Certificates | All Tasks | Import the saved certificate file.
10) Go back to BTS channel and reapply the new certificate to the BizTalk
SendHTTPX transport.
11) Post a request to the remote web site and it gives me the following
warning and error on my event log.

Please help. Thanks so much. Abel Chan


Event Type: Warning
Event Source: BizTalk Server
Event Category: Document Processing
Event ID: 324
Date: 3/17/2005
Time: 10:04:15 AM
User: N/A
Computer: BTS2002
Description:
An error occurred in BizTalk Server.

Details:
------------------------------
[0x80090304] An error occurred during transmission:
The specified client certificate cannot be loaded.
Request information:

Proxy:
Proxy port:80
URL:https://remotetestsite.net/My_submit.asp
Content-Type:text/plain; charset="utf-8"
User name:
Client certificate:com, mycompany, MyCN
Request body:16758 Bytes
Timeout duration (seconds): 140
Error code:80090304

[0x0159] The server encountered a transport error while processing the
messaging port "prtmytestportSend", which uses a transport component with a
ProgID of "BizTalk.SendHTTPX.1".

[0x012b] A transmission attempt failed.

Event Type: Error
Event Source: BizTalk Server
Event Category: Document Processing
Event ID: 324
Date: 3/17/2005
Time: 10:05:13 AM
User: N/A
Computer: BTS2002
Description:
An error occurred in BizTalk Server.

Details:
------------------------------
[0x80090304] An error occurred during transmission:
The specified client certificate cannot be loaded.
Request information:

Proxy:
Proxy port:80
URL:https://remotetestsite.net/My_submit.asp
Content-Type:text/plain; charset="utf-8"
User name:
Client certificate:com, mycompany, MyCN
Request body:16758 Bytes
Timeout duration (seconds): 140
Error code:80090304

[0x0159] The server encountered a transport error while processing the
messaging port "prtmytestportSend", which uses a transport component with a
ProgID of "BizTalk.SendHTTPX.1".

[0x012a] All retry transmissions failed.

[0x80090304] The Local Security Authority cannot be contacted

[0x0156] The server could not finish processing messaging port
"prtmytestportSend".

[0x1730] Suspended Queue ID: "{7B33BD93-2591-4859-B83E-2E5CED6884E3}"

[0x80090304] The Local Security Authority cannot be contacted

0x80041011
[0x1731] The server cannot send a WMI event for the Suspended queue item
"{7B33BD93-2591-4859-B83E-2E5CED6884E3}". The most likely cause is that the
user configured for this submission has insufficient privileges to access WMI.


Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com