Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

disjoint namespace two-tier PKI hierarchy same forest two different domain names

$
0
0

Here is the error that stopped us from going further.

Error on Subordinate:

<v:shapetype coordsize="21600,21600" filled="f" id="_x0000_t75" o:preferrelative="t" o:spt="75" path="m@4@5l@4@11@9@11@9@5xe" stroked="f">
 <v:stroke joinstyle="miter"><v:formulas>  An error was detected while configuring AD CS The AD CS Setup Wizard will need to be rerun to complete he configuration.</v:formulas></v:stroke></v:shapetype>

Cannot create a certificate context using the CA certificate: ASN1 bad tag value met. 0x8009310b (ASN:267 CRYPT_E_ASN1_BadTAG)<v:shapetype coordsize="21600,21600" filled="f" id="_x0000_t75" o:preferrelative="t" o:spt="75" path="m@4@5l@4@11@9@11@9@5xe" stroked="f"><v:stroke joinstyle="miter"><v:formulas>  <v:f eqn="if lineDrawn pixelLineWidth 0">
scenario: <v:shapetype coordsize="21600,21600" filled="f" id="_x0000_t75" o:preferrelative="t" o:spt="75" path="m@4@5l@4@11@9@11@9@5xe" stroked="f">
</v:shapetype>
</v:f></v:formulas></v:stroke></v:shapetype>

Forest name: Matt.ENT(ADDS, DNS, GC)

ROOTCA:

New Domain: Test.Local (ADDS, DNS, GC)

Sub CA

Separate DNS’s non delegated between the 2

Transitive trust

Put DNS conditional forwarder for DNS to contact the main DC

PKI Infrastructure 2 tier using Windows Server 2008 R2 or Windows Server 2012 r2

followed:



AD CS Step by Step Guide: Two Tier PKI
Hierarchy Deployment<o:p></o:p>



http://social.technet.microsoft.com/wiki/contents/articles/15037.ad-cs-step-by-step-guide-two-tier-pki-hierarchy-deployment.aspx<o:p></o:p>



http://social.technet.microsoft.com/wiki/contents/articles/11750.step-by-step-guide-single-tier-pki-hierarchy-deployment.aspx<o:p></o:p>



 <o:p></o:p>



http://technet.microsoft.com/library/hh831348.aspx<o:p></o:p>



http://technet.microsoft.com/en-us/library/cc772393%28v=ws.10%29.aspx#BKMK_AS1


<v:shapetype coordsize="21600,21600" filled="f" id="_x0000_t75" o:preferrelative="t" o:spt="75" path="m@4@5l@4@11@9@11@9@5xe" stroked="f"> <v:stroke joinstyle="miter"><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"><v:shapetype coordsize="21600,21600" filled="f" id="_x0000_t75" o:preferrelative="t" o:spt="75" path="m@4@5l@4@11@9@11@9@5xe" stroked="f">  Cannot go past the SUB CA with this error! Any takes<v:stroke joinstyle="miter">
  <v:formulas>  <v:f eqn="if lineDrawn pixelLineWidth 0">
  <v:f eqn="sum @0 1 0">
  <v:f eqn="sum 0 0 @1">
  <v:f eqn="prod @2 1 2">
  <v:f eqn="prod @3 21600 pixelWidth">
  <v:f eqn="prod @3 21600 pixelHeight">
  <v:f eqn="sum @0 0 1">
  <v:f eqn="prod @6 1 2">
  <v:f eqn="prod @7 21600 pixelWidth">
  <v:f eqn="sum @8 21600 0">
  <v:f eqn="prod @7 21600 pixelHeight">
 <v:f eqn="sum @10 21600 0">
</v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:formulas>
 <v:path gradientshapeok="t" o:connecttype="rect" o:extrusionok="f">
<o:lock aspectratio="t" v:ext="edit">
</o:lock></v:path></v:stroke></v:shapetype> <v:shape alt="cid:image001.png@01CF69D2.4234D100" id="Picture_x0020_2" o:spid="_x0000_i1025" style="width:430.5pt;height:245.25pt;" type="#_x0000_t75">
<v:imagedata o:href="cid:image010.png@01CF6DB7.99786240" src="file:///C:\Users\lc702725\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png">
</v:imagedata></v:shape>
  <v:f eqn="sum @0 1 0">
  <v:f eqn="sum 0 0 @1">
  <v:f eqn="prod @2 1 2">
  <v:f eqn="prod @3 21600 pixelWidth">
  <v:f eqn="prod @3 21600 pixelHeight">
  <v:f eqn="sum @0 0 1">
  <v:f eqn="prod @6 1 2">
  <v:f eqn="prod @7 21600 pixelWidth">
  <v:f eqn="sum @8 21600 0">
  <v:f eqn="prod @7 21600 pixelHeight">
 <v:f eqn="sum @10 21600 0">
</v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:formulas>
 <v:path gradientshapeok="t" o:connecttype="rect" o:extrusionok="f">
<o:lock aspectratio="t" v:ext="edit">
</o:lock></v:path></v:stroke></v:shapetype> <v:shape alt="cid:image001.png@01CF69D2.4234D100" id="Picture_x0020_2" o:spid="_x0000_i1025" style="width:430.5pt;height:245.25pt;" type="#_x0000_t75">
<v:imagedata o:href="cid:image010.png@01CF6DB7.99786240" src="file:///C:\Users\lc702725\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png">
</v:imagedata></v:shape>


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>