Security ForumDiscussion on Windows Server security topics and technologies© 2009 Microsoft Corporation. All rights reserved.Mon, 30 Nov 2009 20:09:12 Za57d8cb2-4aeb-4bc6-9297-3960dc81c028http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/2abdf9ab-cad1-45b2-a7d2-e88781cf9020http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/2abdf9ab-cad1-45b2-a7d2-e88781cf9020HealthCareTechhttp://social.technet.microsoft.com/Profile/en-US/?user=HealthCareTechRoaming profile won't load b/c access denied to url link in favorites folder??Server 2003 SP2 acting as DC, FS, PS.<br/>Clients are all XP Pro SP3<br/>Roaming profiles in use<br/>Folder redirection in use<br/>Problem occurs with *some* user profiles, but not all - doesn't matter which client is used to log in<br/><br/>After getting reports that some users were getting error messages that their roaming profile could to be loaded, I was able to see the 'access denied' error message pointing to <a>\\server\profiles\%user%\Favorites\Links\msn.com</a> and the details that the system was unable to copy the file to the local drive.<br/><br/>Looked like a clear security settings problem (though odd to occur out-of-the-blue).  I checked permissions on the links folder and all are set per &quot;the book&quot; and have been working fine previously.  I attempted to change permissions on the offending Links files but access was denied even though I was physically at the server and logged in as the administrator.  Ownership was set to the Administrators group so I attempted to take ownership as the administrator but access was denied (what the?).  I attempted to delete the file but again, access was denied.<br/><br/>FYI, when checking properties on the individual files, I only see the General tab, not the Web Document or Security tabs (probably b/c I don't have access :-).  So my attempts to take ownership and otherwise change NTFS settings were at the Links folder level and attempting to push settings down to all child folders and files - access denied.<br/><br/>I'm starting to think virus, but I can't find any mention of this behavior anywhere on the web.<br/><br/>This is becoming crippling as it is preventing users from accessing needed files.<br/><br/>Any thoughts?Mon, 23 Nov 2009 16:10:38 Z2009-11-30T20:09:12Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/376974d2-2a25-48c9-a52d-330739003dfehttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/376974d2-2a25-48c9-a52d-330739003dfeHuge123http://social.technet.microsoft.com/Profile/en-US/?user=Huge123Can't log on to W2K Server from Windows 7 ProWe have a Windows 2000 Server sharing files. From my new 7 Pro computer I get an error loging on which says &quot;Logon Failure: unknown username or bad password&quot;. The password and username are correct (same ones been on the W2K server for years and using for years). I tried several other usernames and passwords with the same results. They still work from my XP boxes. Could it be that the machine name is messing up W2K  -  ie Win 7 may be using:  &quot;COMP1\User1&quot; as the usernames instead of just &quot;User1&quot;. I need a workaround or fix. Any Ideas?<br/>ThanksSun, 29 Nov 2009 23:59:01 Z2009-11-30T16:48:29Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/8e64093f-e153-464d-80e8-27099174ac4dhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/8e64093f-e153-464d-80e8-27099174ac4dM.Saadatihttp://social.technet.microsoft.com/Profile/en-US/?user=M.Saadaticreating special limited userHi<br/><br/>How can i create a limited user that only can install software?<br/><br/>RegardsMon, 30 Nov 2009 15:43:30 Z2009-11-30T15:43:31Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/0a05f0ac-fd3b-4755-9417-1c0e055be38bhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/0a05f0ac-fd3b-4755-9417-1c0e055be38bVictor M$http://social.technet.microsoft.com/Profile/en-US/?user=Victor%20M%24Remote shutdown without admin rigths<p>Hi all!<br/>I has been trying to remote shutdown an X server without admin rights but dont work!  if I run the same command with an admin right account works.<br/>The server Its a domain controller (Windows 2003) and in the default domain controller pollicy I allow the follows rights to the user:<br/>-Force shutdown from a remote system<br/>-Log on as a batch job<br/>-Shut down the system<br/>-Log on locally<br/> <br/>Note: I run it through runas by script. Repeat, if I use an admin account in the script works fine....so its a rights issue<br/>If I logon locally with that account I can shutdown the server.<br/>I test it in a lab with a clean domain and do not work.<br/><br/>whats more rights are needed? <br/>whats can I do?<br/>In the security logs showsup 3 logs after run the script<br/>1:<br/>Event Type: Success Audit<br/>Event Source: Security<br/>Event Category: Logon/Logoff <br/>Event ID: 538<br/>Date:  11/29/2009<br/>Time:  10:35:27 PM<br/>User:  NT AUTHORITY\SYSTEM<br/>Computer: DEN-DC1<br/>Description:<br/>User Logoff:<br/>  User Name: DEN-DC1$<br/>  Domain:  CONTOSO<br/>  Logon ID:  (0x0,0x2BB70)<br/>  Logon Type: 3<br/><br/>2:<br/>Event Type: Success Audit<br/>Event Source: Security<br/>Event Category: Account Logon <br/>Event ID: 672<br/>Date:  11/29/2009<br/>Time:  10:35:36 PM<br/>User:  NT AUTHORITY\SYSTEM<br/>Computer: DEN-DC1<br/>Description:<br/>Authentication Ticket Request:<br/>  User Name:  apago<br/>  Supplied Realm Name: CONTOSO.MSFT<br/>  User ID:   CONTOSO\apago<br/>  Service Name:  krbtgt<br/>  Service ID:  CONTOSO\krbtgt<br/>  Ticket Options:  0x40810010<br/>  Result Code:  -<br/>  Ticket Encryption Type: 0x17<br/>  Pre-Authentication Type: 2<br/>  Client Address:  10.x.x.x<br/>  Certificate Issuer Name: <br/>  Certificate Serial Number: <br/>  Certificate Thumbprint: <br/><br/>3:<br/>Event Type: Success Audit<br/>Event Source: Security<br/>Event Category: Account Logon <br/>Event ID: 673<br/>Date:  11/29/2009<br/>Time:  10:35:36 PM<br/>User:  NT AUTHORITY\SYSTEM<br/>Computer: DEN-DC1<br/>Description:<br/>Service Ticket Request:<br/>  User Name:  <a href="mailto:apago@CONTOSO.MSFT">apago@CONTOSO.MSFT</a><br/>  User Domain:  CONTOSO.MSFT<br/>  Service Name:  DEN-CL1$<br/>  Service ID:  CONTOSO\DEN-CL1$<br/>  Ticket Options:  0x40800000<br/>  Ticket Encryption Type: 0x17<br/>  Client Address:  10.x.x.x<br/>  Failure Code:  -<br/>  Logon GUID:  {3ac8eb70-c331-ab85-f64b-6cebd5d30cb5}<br/><br/><br/>Regards!!! </p>Mon, 30 Nov 2009 01:42:56 Z2009-11-30T11:13:07Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/2a3940db-6926-4c63-a0e6-0e859053a1fehttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/2a3940db-6926-4c63-a0e6-0e859053a1feVikram Thakorhttp://social.technet.microsoft.com/Profile/en-US/?user=Vikram%20ThakorWindows Server 2008 R2how to create group policy in windows server 2008 R2Mon, 30 Nov 2009 04:58:34 Z2009-11-30T11:09:01Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/c83fb88e-37b3-4224-90f4-775616f21861http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/c83fb88e-37b3-4224-90f4-775616f21861Ben3297http://social.technet.microsoft.com/Profile/en-US/?user=Ben3297Security adviceHi Guys/Gals<br/><br/>I'm a newbie so be gentle, lol.<br/><br/>I'm reading through the MCTS in order to set up a client/server network within my home-office.  I have 4 staff members and then me.  I've managed to set up, albeit with trial software so far, 5 x windows 7 professional clients and 1 x server 2008 (x86) running AD DS, DHCP and DNS; I've also set up some shared folders for the staff.<br/><br/>I have a Netgear WNR2000 router to which the server has a wired gigabit connection.  The clients access the router via the wireless n speeds.  I currently have McAfee antivirus enterprise 8.7 running on the server and clients.<br/><br/>Should I be investing in firewall software for all the computers or will the one with the router be sufficient?  I have not got to the section in the books about the security wizard just yet.  What websites/tools are available to test my exposure/threat level/vulnerablility etc.<br/><br/>Thanks in advance<br/><br/>CDSun, 29 Nov 2009 10:38:39 Z2009-11-29T10:38:40Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/118e7d54-77c3-4f58-a55f-ac8d0792923fhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/118e7d54-77c3-4f58-a55f-ac8d0792923fimprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseA question about executing Certification Services Monitor script...Hi all;<br/> <br/> <br/> When I execute the Certification Services Monitor script on my Windows Server 2008 box, the following output appears:<br/> <br/> C:\&gt;cscript camonitor.vbs /CAAlive /CACertOK /CACRLOK /KRAOK<br/> Microsoft (R) Windows Script Host Version 5.7<br/> Copyright (C) Microsoft Corporation. All rights reserved.<br/> <br/> 11/27/2009 11:44:21 PM   certutil -ping:OK<br/> 11/27/2009 11:44:21 PM   certutil -pingadmin:OK<br/> 11/27/2009 11:44:21 PM   checking validity of CN=contoso-SERVER01-CA, DC=contoso, DC=com Serial Number:6306185397716BB74FF8060AE6B47895<br/> 11/27/2009 11:44:21 PM   CA Cert OK<br/> 11/27/2009 11:44:22 PM   Retrieve environment variable 'COMPUTERNAME':OK<br/> <strong>11/27/2009 11:44:22 PM   eventcreate /T ERROR /SO &quot;CA Operations&quot; /ID 100 /D &quot;Error: failed to read at least one CDP from certificate:CN=SERVER01.contoso.com&quot; /L Application:OK<br/> 11/27/2009 11:44:22 PM   failed to read at least one CDP from certificate:CN=SERVER01.contoso.com</strong> <br/> 11/27/2009 11:44:22 PM   No KRAs<br/> <br/> C:\&gt;<br/> <br/> Also the output says that it &quot;Failed To Read At Leats One CDP From Certificate&quot;, the PKIView.msc utility does not show any error messages. Please look at the following figure:<br/> <br/> http://cid-3a822dbb941c4298.skydrive.live.com/self.aspx/.Public/1.GIF<br/> <br/> Any idea?<br/> <br/> Thanks<br/> <br/>Sat, 28 Nov 2009 08:50:35 Z2009-11-28T23:30:59Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/360d1529-125b-4300-a446-b9d5c4d04c1chttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/360d1529-125b-4300-a446-b9d5c4d04c1cimprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseError message when executing Certificate Authority Monitor scriptHi all;<br/> <br/> I have Windows Server 2008 Enterprise CA. According to this <a href="http://www.microsoft.com/technet/scriptcenter/solutions/camon.mspx">link</a> , when I execute the script by using the following command, I see an error message:<br/> <br/> <pre>C:\&gt;cscript camonitor.vbs /CAAlive /CACertOK /CACRLOK /KRAOK Microsoft (R) Windows Script Host Version 5.7 Copyright (C) Microsoft Corporation. All rights reserved. 11/27/2009 10:04:22 PM certutil -ping:OK 11/27/2009 10:04:22 PM certutil -pingadmin:OK 11/27/2009 10:04:22 PM CAPICOM is not registered ... quitting 11/27/2009 10:04:22 PM CAPICOM is not registered ... quitting 11/27/2009 10:04:22 PM CAPICOM is not registered ... quitting C:\&gt;</pre> <br/> I have also installed Microsoft <a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=860EE43A-A843-462F-ABB5-FF88EA5896F6&amp;displaylang=en">CAPICOM 2.0</a> . Does this version of the CAPICPM does not supported in Windows Server 2008.If so, which version is compatible?<br/> <br/> Thanks<br/>Sat, 28 Nov 2009 06:21:31 Z2009-11-28T07:28:47Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f5553beb-7c3c-4b9a-8dbc-a45de44de9c9http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f5553beb-7c3c-4b9a-8dbc-a45de44de9c9PM505http://social.technet.microsoft.com/Profile/en-US/?user=PM505All Domain users have access to Domain Controller Admin SharesI just discovered that all of our domain users can access our domain controller C$ drive shares.  I am unsure how long this has been like this, but I do know I (even as network admin) would be prompted for my domain admin credentials to access those shares in the past.<br/><br/>All of our member servers prompt for username &amp; password if we attempt to connect to those admin shares.<br/><br/>I am hoping this was an inadvertant change from our end.  Any ideas on what settings might allow for this activity, and where I can find them?<br/><br/>Our environment:<br/>Windows 2003 SP2<br/>Win 2003 Forest &amp; Domain level.<br/><br/>Thanks!<br/>Matt<br/><hr class="sig">Matt MillerWed, 25 Nov 2009 20:31:23 Z2009-11-27T15:35:38Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/e97229be-2bf2-471b-8da0-6c9404b8c4e4http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/e97229be-2bf2-471b-8da0-6c9404b8c4e4Johnvan3260http://social.technet.microsoft.com/Profile/en-US/?user=Johnvan3260New user profile is corrupted after computer restartHi,<br/><br/>I have a Windows 2003 domain and around 100 XP client machines. I often need to setup an existing user on a different PC and have done so without problem for years.<br/><br/>Now I have two PC's on which I setup new user profiles (domain users) and that works fine until the PC is restarted. On logging on, I get a message saying Windows cannot load the locally stored profile suggesting insufficient security rights or a corrupted profile. All the settings e.g. printer, proxy, mail etc are gone.<br/><br/>I have added these users to the local administrators group to avoid security right problems. This happens every time I setup a user on these two PC's. Setting up the same users on other PC's causes no issues. The existing users on the PC's can still log on without issues.<br/><br/>Any ideas as to what might be happening here? Because it happens on two separate PC's it seems to be related to the domain rather than the PC itself.<br/><br/>Thanks,<br/><br/>JohnFri, 27 Nov 2009 05:42:40 Z2009-11-27T08:27:38Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/614c4d7d-8ac6-44c4-b4df-64d64d890bcahttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/614c4d7d-8ac6-44c4-b4df-64d64d890bcaOla Ehttp://social.technet.microsoft.com/Profile/en-US/?user=Ola%20Euser authentication against NIS Hi Everyone,<br/>We have a lot of Linux servarar and a cupple of Windows servrar, in our server park.<br/>All our shared folders have been on the linux mashines, and the authentication is done via NIS.<br/><br/>We have now come to a issue, we have a new program that need's to be installed on a windows server 2008, and needs to have a share on the machine.<br/>We need to be able to authenticate users that connects to the share againts the NIS on the Linux machine. How do we do this??<br/><br/>Polises shall be applied on a group level. <br/><br/>Best regards<br/>OlaWed, 25 Nov 2009 13:58:50 Z2009-11-27T08:04:04Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/97bd8025-b3e4-48f3-ba80-65a9bf310aechttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/97bd8025-b3e4-48f3-ba80-65a9bf310aecArie de Haanhttp://social.technet.microsoft.com/Profile/en-US/?user=Arie%20de%20HaanWindows XPsp3 client cannot obtain certificate from Windows 2008R2 Enterprise Issuing CA<p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>When requesting a certificate with a Windows XP sp3 client through the webinterface, the issued certificate cannot be installed. The error dialog box states:<br/>Unable to install the certificate: Error: 0x80090008 (this happens when using IE6,7 or 8)<br/>When doing the same procedure from a Windows 7 (IE8) client, the certificate can be installed </span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>As far as I could research this means that an invalid algorithm is used. <br/><br style=""><br style=""></span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>The errors i see on the IssuingCA are the following. This occurs around the same time when a certificate is requested</span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>When a certificate is requested which needs approval it ends up in de Pending Requests (e.g. this is requestid 141). When this request is Issued, it is displayed in the Issued certificates, and it can be seen by the client when it requests the status. What happens on the CA is that another a requested 142 ends up in the Failed Requests list due to Request Status Code:“The certificate has invalid policy. 0x800b0113 (-2146762477)” and Request Disposition Message: “Requested by &lt;domain&gt;\&lt;user&gt; Invalid Application Policies: 1.3.6.1.4.1.311.21.5”. This is also represented in the Application Windows eventlog.</span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US> </span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>I also see the error on the CA (the same invalid application policy message) when using pkiview.msc and when hitting the refresh option in pkiview.msc on this IssuingCA.</span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US> </span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>What I found is:<br/>When requesting a certificate with for instance Windows Xp or Windows 7, the Issuing CA needs a CAExchange certificate, as stated in </span><span style="text-decoration:underline"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:blue;font-size:8pt" lang=EN-US><a href="http://social.technet.microsoft.com/Forums/en-US/&#11;http:/msdn.microsoft.com/en-us/library/cc249706(PROT.10).aspx#endNote13"><br/><span style="color:#0000ff">http://msdn.microsoft.com/en-us/library/cc249706(PROT.10).aspx#endNote13</span></a></span></span><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US><br/><br/>a windows client needs the CA to able to present a CA Exchange OID = 1.3.6.1.4.1.311.21.5 certificate<br/><br/>in <br/><a href="http://msdn.microsoft.com/en-us/library/cc250045(PROT.10).aspx#id13">http://msdn.microsoft.com/en-us/library/cc250045(PROT.10).aspx#id13</a><br/>is states that a 2008R2 will automatically makes such a certificate</span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>The CA architecture is. offline RootCA, offline PolicyCA, enterprise IssuingCA. RootCA &amp; PolicyCA have no entry for enhancekeyusageextensions in the CAPolicy.inf, IssuingCA has enhancekeyusageextensions in the CAPolicy.inf. 1.3.6.1.5.5.7.3.1, 1.3.6.1.5.5.7.3.2, 1.3.6.1.5.5.7.3.3, 1.3.6.1.4.1.311.10.3.12</span></p> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>So there is possibly a configuration error and would like to correct the CAExchange OID issues. </span></p> <span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>But far more important is to solve the error with the Windows XP sp3 client. I don’t know if these two are related.</span><hr class="sig">Greetz, <br/> <br/> Arie de Haan <br/> MVP SCOM <br/> This posting is provide &quot;AS IS&quot; with no guarantees, warranties, rigths etc. <br/> Wed, 18 Nov 2009 15:14:53 Z2009-11-26T22:29:59Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/7035d230-4f3b-4c62-b460-4fa40223b1a5http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/7035d230-4f3b-4c62-b460-4fa40223b1a5Pete Sm1thhttp://social.technet.microsoft.com/Profile/en-US/?user=Pete%20Sm1thInvalid certificate when using Non Repudiation in certificateWhy is it not possible to specify &quot;Signature is proof of origin(non repudiation)&quot; as a Key Usage Extension when a certificate has the Request Handling set to &quot;Signature and smartcard Logon&quot;? This setting is greyed out and appears to be not set.<br/><br/><br/>Sorry if this is a no brainer.<br/><br/><br/><br/><br/><br/>Thu, 26 Nov 2009 10:34:09 Z2009-11-26T15:13:22Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/4b3898b0-7038-431d-afed-ed2505288ed4http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/4b3898b0-7038-431d-afed-ed2505288ed4Saguishttp://social.technet.microsoft.com/Profile/en-US/?user=SaguisCannot start my computer<p align=left><font face=Arial size=2>Hi, This is Saguis, my laptop don't start I only can see a message... &quot;Windows cannot start (Windows Root) System32 hal.dll&quot;, and if I try the Safe mode the screen won't show anything, I have the Windows xp CD, but the laptop don't read it, shuold I do something else before?, or is there anything else I need to do becase F8 don't let me do anything, I try all options and is not responding, What do I need to restart my computer?</font></p> <p align=left> </p> <p align=left> </p> <p align=left> </p>Sat, 16 Feb 2008 04:57:08 Z2009-11-26T14:10:07Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/6e3883f0-03e6-4207-a674-aaf404ab5069http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/6e3883f0-03e6-4207-a674-aaf404ab5069w.alsburyhttp://social.technet.microsoft.com/Profile/en-US/?user=w.alsburyCertificate Services will not start becauseI am in the middle of server moves and have an error on my CA server which reads<br/><br/>Certificate Services will not start because the revocation server is offline. <br/><br/>I suspect that the server in question is now scrap, how can I recover this situation without having to buy new certificates?Thu, 26 Nov 2009 09:57:45 Z2009-11-30T07:46:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/af88b11c-628d-49cf-9441-67362dc2bc7fhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/af88b11c-628d-49cf-9441-67362dc2bc7fArunkumar GMhttp://social.technet.microsoft.com/Profile/en-US/?user=Arunkumar%20GMHow to renew the certificate issued by a standalone 2003 Enterprise Edition server <p>How to renew the certificate issued by a standlone CA</p> <p>Hi Everyone,</p> <p>I have configured a standalone CA and issued ssl certificates<br/>to end users who are Anonymous users All are made to requested through web page Enrollment then we created the certificate and sent them through mail along with private key. Now i need to renew <br/>the issued  certificates validity.(all the certificates have few more months validity time left out).</p> <p>I followed the following renewal process from Tech net.</p> <p>Steps I followed:</p> <p>1) Open Internet Explorer</p> <p>2) In Address, type <a href="http://servername/certsrv">http://servername/certsrv</a>, where servername is the name of the Windows 2000 Web server where the certification authority (CA) you want to access is located</p> <p>3) Click Request a certificate, and then click advanced certificate request</p> <p>4) Click Submit a certificate request using a base64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file<br/>Here i used submit a renewal request by using a base-64-encoded PKCS # 7 file .</p> <p> <br/>5) Do one of the following:</p> <p> Open Notepad. On the File menu, click Open. Select the PKCS #10 or PKCS #7 file and click Open. On the Edit menu, click Select all, and then, on the Edit menu, click Copy. On the Web page, click in the Saved request scroll box. On the Edit menu, click Paste to paste the contents of certificate request into the scroll box.</p> <p> If your Web browser security settings do not prohibit a Web page from accessing your disk, you can click Browse for a file to insert to locate the file you want to use for the certificate request. If you get a warning about the ActiveX control, click Yes to allow it to run, then click Browse. After locating and selecting the file you want to use for the certificate request, click Read!. On the Web page, click Read! to paste the contents of the file into the scroll box. See the note about using Browse.</p> <p>6) If you are connected to an enterprise CA, choose the certificate template you want to use.<br/>7) Click Submit.</p> <p><br/>Here after step NO 5 I am getting the error message as follows :</p> <p>COM Error info:<br/>CCertrequest:submit the data is invalid 0x8007000d(WIN32:13)</p> <p>Suggested cause :</p> <p> The certificate request contained bad data.if you are submitting a saved request,make sure that the request<br/>contains no garbage data outside the BEGIN and END tags, and that the file containing the saved request is not corrupted.</p> <p>I kindly invite the suggesstions .</p> <p>Thanks &amp; Regards<br/>Arunkumar.G</p>Thu, 19 Nov 2009 09:55:15 Z2009-11-26T07:29:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/4699b10f-75a5-4e04-9f1f-573fe13a41d4http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/4699b10f-75a5-4e04-9f1f-573fe13a41d4Rimvydashttp://social.technet.microsoft.com/Profile/en-US/?user=RimvydasMultiple enterprise subordinate CAs in one domain<span style="color:#1f497d">Lets imagine that i have following pki stucture – one root ca (standalone) and two enterprise Cas. One of these enterprise ca‘s has domain controller authentication template published and the other doesn‘t. As you may now domain controllers autoenroll certificates according this template from time to time. So my question would be – will domain controller be able to find correct CA in AD with  domain controller authentication  template enabled and will it be able to autoenroll certificate? I affraid that it can stuck on CA with this template disabled and fail with autoenrollment</span> <span style="font-family:Wingdings;color:#1f497d">L</span> <span style="color:#1f497d"> Thanks.</span>Tue, 17 Nov 2009 08:52:56 Z2009-11-26T05:11:19Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/cbc50b9c-8973-4953-8ec8-6c9ba126b1d2http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/cbc50b9c-8973-4953-8ec8-6c9ba126b1d2IceFactorhttp://social.technet.microsoft.com/Profile/en-US/?user=IceFactorCan a Standalone & Enterprise Certificate Authority both run on the same domain?Current running a standalone certificate authority on the primary DC which is Windows 2003 Std.  Need to upgrade to an Enterprise Certificate authority on Windows 2003 Ent.  Both certificate authorities would be on the same domain and domain controllers.  Will running both a Standalone and Enterprise certificate authority on the same domain cause any issues? After all certificates have been duplicated I would take the Standalone certificate authority down.Tue, 24 Nov 2009 20:19:33 Z2009-11-26T17:47:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/768f3352-8830-4d41-846c-bdf2727da080http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/768f3352-8830-4d41-846c-bdf2727da080PsharkAuburnhttp://social.technet.microsoft.com/Profile/en-US/?user=PsharkAuburnHow do you renew certificates issued by Standalone CA<p>CA Server is Windows Server 2008 in Standalone mode, clients are both Windows XP and Windows Vista.<br/><br/>How do you renew expiring certificates when your CA is a standalone CA. Any attempts in the MMC snap-ins come back with &quot;request contains No Certificate Template info&quot; which makes sense because Standalone CA's do not use templates. So how do you renew a certificate? Or specifically, how do you create a certificate request for renewal using command-line tools which I'm guessing is the only option? Any help appreciated. </p>Tue, 19 May 2009 20:37:43 Z2009-11-25T14:01:29Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/d1c467ac-289a-4fdc-945f-4216eec74399http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/d1c467ac-289a-4fdc-945f-4216eec74399carfandhttp://social.technet.microsoft.com/Profile/en-US/?user=carfandNPS Server CertificateI'm trying to follow the steps to use NPS for secure wireless access-&gt;http://technet.microsoft.com/en-us/library/cc771696.aspx.  I'm following the steps to setup <span style="color:#0033cc">PEAP-MS-CHAP v2 Wireless Authentication.</span> I'm at the part where I'm trying to setup an enterprise CA and issue a new certificate template that can be used by the RADIUS server.  The new template is supposed to be based on the RAS and IAS template.   I follow the steps to duplicate and customize the RAS and IAS template.  When I go to the CA and choose New-&gt;Cert template to issue, only the version 1 templates are available to issue to the CA.  <br/><br/>I'm running Server 2008 SP2 Standard.  The Ent. CA is also running DS.  <br/><br/>Maybe i'm running into his problem because I'm using the standard edition of server 2008?  If this is the case, what options do I have?  Thank you.Tue, 24 Nov 2009 23:33:11 Z2009-11-27T07:06:56Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/53c08e0f-942b-4488-b4fd-e191773e63aehttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/53c08e0f-942b-4488-b4fd-e191773e63aebethg-shttp://social.technet.microsoft.com/Profile/en-US/?user=bethg-sA Need to Customize Certreq Command and .inf FileHi all;<br/><br/>I have a need to change the following OID value for osVersion, <span lang=EN> <p>1.3.6.1.4.1.311.13.2.0</p> </span><br/>Using certreq utility on the command line of Windows 2003 (2008 as well) to generate a csr, this OID is set to:<br/><br/><span lang=EN> <p>5.2.3790.2</p> </span>I need to change it to something more like:<br/><br/><span lang=EN> <p>6.0.6001.2</p> </span>But have no idea how to do this in the research I have done on TechNet. I cannot see how to do this in a .inf file from the white paper; and I do not have templates availalbe so I cannot/have not explored that option.<br/><br/>Thanks in advance if anyone can respond.<br/><br/>Tue, 24 Nov 2009 23:36:25 Z2009-11-30T13:02:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f1059ae1-fcb9-4bb7-932e-e04d900da682http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f1059ae1-fcb9-4bb7-932e-e04d900da682RevoBasherhttp://social.technet.microsoft.com/Profile/en-US/?user=RevoBasherGuest Account Audit<p>Is it possible to audit who is enabling the guest account on a 2003 R2 Server? <br/><br/>Thanks!</p>Tue, 24 Nov 2009 16:16:05 Z2009-11-25T07:21:50Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/c968cdfc-1c7b-48d7-973c-7d6b6ca20879http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/c968cdfc-1c7b-48d7-973c-7d6b6ca20879Niels Werner Mortensenhttp://social.technet.microsoft.com/Profile/en-US/?user=Niels%20Werner%20MortensenForced logoutsIn a Windows 2003 domain users (out of the blue) get logged out with a resulting Event ID: 680 and Error Code: 0xC0000234 in the security log. I have been trying to find a pattern in who gets logged out with little success. The only new &quot;thing&quot; I can think of, is that we're now getting Windows 7 PC's in the domain. Our 2 DCs are fully patched, but getting on a bit (Don't we all)  <br/><hr class="sig">Niels Werner MortensenTue, 24 Nov 2009 17:09:30 Z2009-11-25T07:11:57Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/5f05471f-edee-4be5-83ac-360a3c7c5e73http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/5f05471f-edee-4be5-83ac-360a3c7c5e73ricc363http://social.technet.microsoft.com/Profile/en-US/?user=ricc363Cannot run Scheduled Tasks from user account<p>I deployed a Windows 2003 Server STD R2 as a file server, just in workgroup. For security reason, I created a user account to logon, instead using the Administrator.<br/>Is it correct? But I can't run scheduled tasks like antivirus scanning and UPS monitoring. I use Clamwin antivirus and Upsilon 2000 fo UPS. The command Run As doesn't solve the problem. Is there a solution or I must necessarily use Administrator session?</p>Fri, 20 Nov 2009 07:05:47 Z2009-11-27T01:47:20Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/8a058f40-a5b7-441d-a85a-e81396ecf2c8http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/8a058f40-a5b7-441d-a85a-e81396ecf2c8gadgets906http://social.technet.microsoft.com/Profile/en-US/?user=gadgets906small buisness server 2003 configure rras firewall to allow exception for vnc application<p>Running SB 2003 two nic cards as a router, firewall enabled through rras, have vnc installed and was working remotely until recent microsoft update. now when attempting to configure vnc, error message appears stating firewall need to have exception for program vnc. Could really use some advise as to where to make the exception and add the necessary ports?</p> <p> </p>Sun, 22 Nov 2009 23:33:02 Z2009-11-25T02:00:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/efb26fd2-32a0-4071-8e79-9f53f8b1964dhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/efb26fd2-32a0-4071-8e79-9f53f8b1964dSpinnergirlhttp://social.technet.microsoft.com/Profile/en-US/?user=SpinnergirlWhat is WGASETUP.EXEI have blocked this program and need to know what it is? I think I have been hacked and Phished and then this popped up so I blocked it. Is it a program I need? I am at my wits end trying to figure out everything that is going on. How do I get rid of a hacker? I think my Mcafee product has been corrupted as well.<br/>Thanks for any help! Please reply ASAP!Fri, 20 Nov 2009 22:27:48 Z2009-11-25T00:39:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/b555bb0e-79b4-4c05-9a2e-bbb6b5f1b9b2http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/b555bb0e-79b4-4c05-9a2e-bbb6b5f1b9b2obnetadminhttp://social.technet.microsoft.com/Profile/en-US/?user=obnetadminWireless question<p>Don't know if this is the correct forum but I will start here. I have a single forest single domain Windows Server 2003 AD environment.  I have a seperate subnet for wireless traffic on one of my network segments. We are using Proxim AP-4000 access points. Is there a way (either through DHCP or Group Policy) to block unauthorized devices (IPods, IPhones, etc) from obtaining an IP address? Or should I think about setting up a RADIUS server? Any ideas?<br/></p>Thu, 30 Jul 2009 19:25:31 Z2009-11-24T23:41:33Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/da4a788d-7668-40f7-9cd7-72f7e56aaa25http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/da4a788d-7668-40f7-9cd7-72f7e56aaa25Shawn Allinhttp://social.technet.microsoft.com/Profile/en-US/?user=Shawn%20AllinShare access questionI have several shares on a 2003 server in AD controlled by simple share permissions.  When I want to give someone access, I either add their name directly, or put their name into an AD security group which in turn is listed in the permissions of the share.  In the first case, access is granted immediately.  In the second case, it will sooner or later happen.  Is there a way to force the rereading (or whatever) of the group members to make the access happen quickly?Tue, 24 Nov 2009 17:09:04 Z2009-11-24T19:39:49Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/5d69ef47-103a-4449-b675-11fa6ca29356http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/5d69ef47-103a-4449-b675-11fa6ca29356imprisehttp://social.technet.microsoft.com/Profile/en-US/?user=impriseManage Revocation Data by Using Local CRLsHi all;<br/> <br/> In the following Microsoft document we read that: To modify certificate data in a local CRL, we must right click our Revocation Configuration and then select &quot;Local Certificate Revocation List&quot; form the menu. The problem is I cannot find this option. What is the problem?<br/> <br/> http://technet.microsoft.com/en-us/library/cc753253.aspx<br/> <br/> <br/> I use Windows Server 2008 Enterprise Edition with SP2.<br/> <br/> any idea?<br/> <br/> Thanks<br/> <strong> </strong>Tue, 24 Nov 2009 15:44:42 Z2009-11-24T17:05:07Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f22372bf-8394-4f2e-a07e-6cc53c20f6d9http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f22372bf-8394-4f2e-a07e-6cc53c20f6d9KJanneyhttp://social.technet.microsoft.com/Profile/en-US/?user=KJanneykb973037<span><strong>What are the prerequisites which could cause kb973037 to fail to apply?</strong></span>Mon, 23 Nov 2009 23:28:58 Z2009-11-25T08:12:22Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/44166870-2c66-4626-b59f-de26ea1cf239http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/44166870-2c66-4626-b59f-de26ea1cf239Amjad Shaikhttp://social.technet.microsoft.com/Profile/en-US/?user=Amjad%20ShaikHow to Find Domain users with Local Administrator Rights Hello Friends,<br/> <br/> We have found some of the domain users are having local admin rights on their PCs.<br/> <br/> We need to find out the users those who are member of Administrator Account &amp; remove them<br/> <br/> Is there any tool to find out...???<br/> <br/> Our Domain is Windows 2003 Enterprize R2.<br/> <br/> Kindly help me ..Thanks in Advanced.<hr class="sig">Regards, AmjadMon, 23 Nov 2009 08:07:04 Z2009-11-27T02:15:50Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/81fece9f-ff84-487b-82dc-a2db49e14872http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/81fece9f-ff84-487b-82dc-a2db49e14872HRM-LAhttp://social.technet.microsoft.com/Profile/en-US/?user=HRM-LAMac clients can't authenticate to SBS 2008Hi,<br> We have a brand new SBS 2008 in a small office environment, also handling AD DS, DNS, and some file shares. The clients include several OS X 10.4 and 10.5 machines, and it's evident that out of the box, Server 2008 doesn't let them connect over SMB. <br> I also posted this in the file services forum, but it seems to be a security issue just as much.<br> <br> <ul> <li>It's an audit failure; on the client side &quot;Could not connect to the server because the name or password is not correct.&quot; On the server side, event ID 4625.</li> <li>Window clients can connect fine, using the same credentials I'm feeding the Mac.</li> <li>Giving &quot;Everyone&quot; access permissions to the folder didn't make any difference.</li> <li>Same problem with 10.4 and 10.5.</li> </ul> <br> <strong>Event logs:</strong> (FQDN renamed)<br> <br> &lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>   &lt;System&gt;<br>     &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br>     &lt;EventID&gt;4625&lt;/EventID&gt;<br>     &lt;Version&gt;0&lt;/Version&gt;<br>     &lt;Level&gt;0&lt;/Level&gt;<br>     &lt;Task&gt;12544&lt;/Task&gt;<br>     &lt;Opcode&gt;0&lt;/Opcode&gt;<br>     &lt;Keywords&gt;0x8010000000000000&lt;/Keywords&gt;<br>     &lt;TimeCreated SystemTime=&quot;2009-03-20T01:02:42.961Z&quot; /&gt;<br>     &lt;EventRecordID&gt;4266289&lt;/EventRecordID&gt;<br>     &lt;Correlation /&gt;<br>     &lt;Execution ProcessID=&quot;600&quot; ThreadID=&quot;700&quot; /&gt;<br>     &lt;Channel&gt;Security&lt;/Channel&gt;<br>     &lt;Computer&gt;myserver.mydomain.local&lt;/Computer&gt;<br>     &lt;Security /&gt;<br>   &lt;/System&gt;<br>   &lt;EventData&gt;<br>     &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubjectUserName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubjectDomainName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubjectLogonId&quot;&gt;0x0&lt;/Data&gt;<br>     &lt;Data Name=&quot;TargetUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br>     &lt;Data Name=&quot;TargetUserName&quot;&gt;MAC&lt;/Data&gt;<br>     &lt;Data Name=&quot;TargetDomainName&quot;&gt;MYDOMAIN&lt;/Data&gt;<br>     &lt;Data Name=&quot;Status&quot;&gt;0xc000006d&lt;/Data&gt;<br>     &lt;Data Name=&quot;FailureReason&quot;&gt;%%2313&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubStatus&quot;&gt;0xc0000064&lt;/Data&gt;<br>     &lt;Data Name=&quot;LogonType&quot;&gt;3&lt;/Data&gt;<br>     &lt;Data Name=&quot;LogonProcessName&quot;&gt;NtLmSsp &lt;/Data&gt;<br>     &lt;Data Name=&quot;AuthenticationPackageName&quot;&gt;NTLM&lt;/Data&gt;<br>     &lt;Data Name=&quot;WorkstationName&quot;&gt;\\MACCLIENT&lt;/Data&gt;<br>     &lt;Data Name=&quot;TransmittedServices&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;LmPackageName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;KeyLength&quot;&gt;0&lt;/Data&gt;<br>     &lt;Data Name=&quot;ProcessId&quot;&gt;0x0&lt;/Data&gt;<br>     &lt;Data Name=&quot;ProcessName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;IpAddress&quot;&gt;192.168.0.30&lt;/Data&gt;<br>     &lt;Data Name=&quot;IpPort&quot;&gt;49836&lt;/Data&gt;<br>   &lt;/EventData&gt;<br> &lt;/Event&gt;<br> <br> <br> &lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>   &lt;System&gt;<br>     &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br>     &lt;EventID&gt;4625&lt;/EventID&gt;<br>     &lt;Version&gt;0&lt;/Version&gt;<br>     &lt;Level&gt;0&lt;/Level&gt;<br>     &lt;Task&gt;12544&lt;/Task&gt;<br>     &lt;Opcode&gt;0&lt;/Opcode&gt;<br>     &lt;Keywords&gt;0x8010000000000000&lt;/Keywords&gt;<br>     &lt;TimeCreated SystemTime=&quot;2009-03-20T01:02:42.961Z&quot; /&gt;<br>     &lt;EventRecordID&gt;4266288&lt;/EventRecordID&gt;<br>     &lt;Correlation /&gt;<br>     &lt;Execution ProcessID=&quot;600&quot; ThreadID=&quot;700&quot; /&gt;<br>     &lt;Channel&gt;Security&lt;/Channel&gt;<br>     &lt;Computer&gt;myserver.mydomain.local&lt;/Computer&gt;<br>     &lt;Security /&gt;<br>   &lt;/System&gt;<br>   &lt;EventData&gt;<br>     &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubjectUserName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubjectDomainName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubjectLogonId&quot;&gt;0x0&lt;/Data&gt;<br>     &lt;Data Name=&quot;TargetUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br>     &lt;Data Name=&quot;TargetUserName&quot;&gt;MAC&lt;/Data&gt;<br>     &lt;Data Name=&quot;TargetDomainName&quot;&gt;MYDOMAIN&lt;/Data&gt;<br>     &lt;Data Name=&quot;Status&quot;&gt;0xc0000225&lt;/Data&gt;<br>     &lt;Data Name=&quot;FailureReason&quot;&gt;%%2304&lt;/Data&gt;<br>     &lt;Data Name=&quot;SubStatus&quot;&gt;0x0&lt;/Data&gt;<br>     &lt;Data Name=&quot;LogonType&quot;&gt;3&lt;/Data&gt;<br>     &lt;Data Name=&quot;LogonProcessName&quot;&gt;<br>     &lt;/Data&gt;<br>     &lt;Data Name=&quot;AuthenticationPackageName&quot;&gt;NTLM&lt;/Data&gt;<br>     &lt;Data Name=&quot;WorkstationName&quot;&gt;\\MACCLIENT&lt;/Data&gt;<br>     &lt;Data Name=&quot;TransmittedServices&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;LmPackageName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;KeyLength&quot;&gt;0&lt;/Data&gt;<br>     &lt;Data Name=&quot;ProcessId&quot;&gt;0x0&lt;/Data&gt;<br>     &lt;Data Name=&quot;ProcessName&quot;&gt;-&lt;/Data&gt;<br>     &lt;Data Name=&quot;IpAddress&quot;&gt;192.168.0.30&lt;/Data&gt;<br>     &lt;Data Name=&quot;IpPort&quot;&gt;49836&lt;/Data&gt;<br>   &lt;/EventData&gt;<br> &lt;/Event&gt;<br> <br> <br> Mon, 23 Mar 2009 17:39:31 Z2009-11-24T11:21:24Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/10515a3a-22ea-4346-9eff-dc4d08f930edhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/10515a3a-22ea-4346-9eff-dc4d08f930edPSJA2007http://social.technet.microsoft.com/Profile/en-US/?user=PSJA2007Replacing root CA above Windows Server 2003 subordinate issuing CAs<p>Hi,</p> <p>I did post a related question at <a href="http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/dfe1f541-e3b2-42b5-bd3b-7a7d0f7a7e66">http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/dfe1f541-e3b2-42b5-bd3b-7a7d0f7a7e66</a> but I guess as it mentions HSMs its not getting much response so Ive asked a more generic question here:</p> <p>We have lost the ability to export our private key for the root CA (for now it can still be used for signing but see other post if more info needed) so we will need to have a completely new root CA and the old one removed.</p> <p>My question is what implications will this have on the subordinate issuing CAs and all the certificates it has issued if we have to replace the root?</p> <p>I guess we will still keep the old root CA cert as a trusted root but what about root CA CRL publishing etc, will that be required for the certificated issued by the subordinate CAs?<br/><br/>Thanks for any help</p>Thu, 19 Nov 2009 12:10:57 Z2009-11-27T06:06:17Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb8cf70-577b-4c72-b751-b6824fe8dd9dhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9cb8cf70-577b-4c72-b751-b6824fe8dd9dLuke Zillmanhttp://social.technet.microsoft.com/Profile/en-US/?user=Luke%20ZillmanSecurity TemplatesHi everyone,<br/><br/>If I create a security template, one of the settings for example might be &quot;people allowed to access the registry&quot; (I just made this setting up)<br/>now it might list 'administrators', backup operators, but what if it has something like MACHINES_NAME/IIS_USER (or something like that)... what if it lists<br/>that specific machines IIS account? - what if I then 'deploy this policy' via group policy to 100 other machines, will that setting have the 'exact name'<br/>of the origional machine (MACHINES_NAME/IIS_USER or would it have the 'new name' of the machine the policy was applied to?<br/><br/>thanks,<br/><br/>Luke.Thu, 19 Nov 2009 03:21:28 Z2009-11-27T06:06:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f26aa5fb-e023-4982-a6a4-6107b00b1b6chttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/f26aa5fb-e023-4982-a6a4-6107b00b1b6cAnahitaShttp://social.technet.microsoft.com/Profile/en-US/?user=AnahitaSLimit the number of User's Certificate ( in PKI)<p class=MsoNormal style="margin:0in 0in 10pt"><span style="font-family:Calibri;font-size:small">We are using PKI in our organization. Although it has been set for Domain users to receive their certificates through Active Directly automatically, but they can also request for email encryption and signature certificates through web enrollment and the website. Now we must limit each user to have only one certificate for email encryption and one for email signature. I mean users should not have more than one certificate for each of the features. I could not find anything which help me on limiting users for their certificate requests! How can we limit users to receive one and only one certificate based<span style="">  </span>on their requests?<br/>thanks</span></p>Tue, 24 Nov 2009 05:50:04 Z2009-11-26T01:57:48Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/4adad855-d29a-461a-b28a-bb67217409c7http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/4adad855-d29a-461a-b28a-bb67217409c7Rohit Goelhttp://social.technet.microsoft.com/Profile/en-US/?user=Rohit%20GoelClearing specific event log from Eventviewer Hi Team, <br/><br/>Is there any way to clear a specific event log entry from event viewer inplace of clearing the entire log? Is there any way to do it from registry or using any tool available? <br/>Any suggestions will be highly appreciated. <br/><br/>Regards,<br/>RohitMon, 23 Nov 2009 23:47:28 Z2009-11-27T01:33:03Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/ed3b0502-89db-4786-a541-72b5e65886e8http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/ed3b0502-89db-4786-a541-72b5e65886e8Konrad Hallhttp://social.technet.microsoft.com/Profile/en-US/?user=Konrad%20HallSetting up a brand new PKI - WS08 R2 - few questionsHi all,<br/><br/>I've been digging through a lot of documents before starting a PKI implementation. I'll be using a two tier approach ( Root CA offline, two issuing CA ) running on Windows Server 2008 R2. Now I've got the big picture pretty clear but I need a few hints.<br/><br/>1. As stated before I will be using two tier approach. I will only be using one CDP, wich will be a HTTP URL hosted on two servers in a DMZ ( load balancing ). I also would like to use the R2 feature Certificate Web Enrollment Services ( CES ) which I guess would be installed on the same servers were the CDP is hosted. Will that be sufficient for all Web Enrollment or will I also have to install the &quot;old&quot; Web Enrollment feature? <br/><br/>2. If I also have to use the &quot;old&quot; Web Enrollment, where would you recommend installing that feature, on the Issuing CA or on a seperate server?<br/><br/>3. I will also be using OCSP, installed on the same servers hosting the CDP. Does the server running the OCSP need to be domain joined?<br/><br/>4. Is it possible to publish delta crl to HTTP CDP?<br/><br/>5. With regards to NDES, is that something I have to take into consideration right now or can I implement that feature at a later stage after the PKI has been launched?<br/><br/>Best Regards<br/>Konráð Hall<hr class="sig">Konráð HallMon, 23 Nov 2009 11:48:04 Z2009-11-25T07:44:53Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9f5b685a-e140-4fa6-a691-4d0dee35364ehttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/9f5b685a-e140-4fa6-a691-4d0dee35364eReppiehttp://social.technet.microsoft.com/Profile/en-US/?user=ReppiePKI for two different forestsI am putting together PKI design for mostly internal clients but some will be on a DMZ.  I was looking to have an offline Root CA with two sub CAs, one in the internal forest and one in the DMZ forest.  I was going to use http and ldap CDPs.  Does it make sense to use http and ldap or just http since the subs are in different forests?  Is the only value with ldap CDP just if all clients are on the same internal forest?  Thank you.Mon, 23 Nov 2009 20:43:10 Z2009-11-30T02:34:15Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/265b2b12-36d5-42ab-b97e-06a3278a3a27http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/265b2b12-36d5-42ab-b97e-06a3278a3a27Robert_Rayhttp://social.technet.microsoft.com/Profile/en-US/?user=Robert_RayEffective PermissionsHi<br/><br/>Can anyone help me out. If you configure a share level permission of change and a ntfs permission of Modify. Which of the 2 is the most restrictive and why?<br/><br/>I think it would be change but I am unable to back up this thinking with any resource so I could be completly wrong. I would be very grateful if you have a link to perhaps a technect article to help out.<br/><br/>Regards<br/><br/>RobertSat, 21 Nov 2009 18:10:08 Z2009-11-25T01:36:30Zhttp://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/8f583e45-e1cd-4d74-a95c-533558d3cc56http://social.technet.microsoft.com/Forums/en-US/winserversecurity/thread/8f583e45-e1cd-4d74-a95c-533558d3cc56swakefieldhttp://social.technet.microsoft.com/Profile/en-US/?user=swakefieldHow to deploy wmi namespace security in domain, multlple servers?Hi, <br/> I have a process that is doing remote monitoring via wmi. I am fully aware of the setting up the security and allowing dcom remotely. <br/> <br/> My question is: is there any way to set WMI Namespace security across a domain or enterprise? I do not want to have to use an domain administrator user account for this monitoring, goes against the least privilege principle.<br/> <br/> The only official microsoft way I can find is via <span class=userInput>wmimgmt.msc (see link </span> http://support.microsoft.com/kb/295292).<br/> <br/> It seems that this is very unfriendly to a large organization.Mon, 09 Nov 2009 21:58:25 Z2009-11-23T17:39:38Z