Microsoft KB Archive/922423

= FIX: Error message when you try to directly send a new SSL server certificate request to a CA service after you upgrade from Exchange 2000 Server to Exchange Server 2003: &quot;Access is denied&quot; =

Article ID: 922423

Article Last Modified on 10/30/2007

-

APPLIES TO


 * Microsoft Internet Information Services 5.0
 * Microsoft Exchange Server 2003 Service Pack 2

-



SYMPTOMS
Consider the following scenario:
 * You upgrade a Web server from Microsoft Exchange 2000 Server to Microsoft Exchange Server 2003 Service Pack 2 (SP2).
 * The Web server is also running Microsoft Internet Information Services (IIS) 5.0 and Microsoft Outlook Web Access (OWA).
 * You try to directly send a new Secure Sockets Layer (SSL) server certificate request to an online root Microsoft Windows enterprise certification authority (CA) service.

In this scenario, you may receive the following error message:

Access is denied: 0x80070005

Additionally, when you try to send the certificate request by using the path http://localhost/certsrv or the path http:// /certsrv, you may receive the following error message:

Fatal Error

Note These are the only two methods that you can use to request a certificate from a CA service.

This problem may occur if the following conditions are true:
 * Microsoft Windows 2000 Server Service Pack 4 (SP4) is installed on both the Web server and the computer that is running the CA service.
 * You use SSL to communicate with OWA on the Web server.

You experience this problem although OWA worked correctly when you used Exchange 2000 Server.

Note The Web server is the source of the certificate request. Any user who tries to request a certificate for a Web site on the Web server is affected by this problem.



CAUSE
This problem occurs because there is an invalid certificate on the Web server that is running Exchange Server and IIS 5.0, and the CA service is stopped on the CA server. Therefore, the CA service cannot provide a valid certificate.



RESOLUTION
To resolve this problem, use the following methods. Try method 1 first. If method 1 does not resolve the problem, stop the Certificate Services service, and then go to method 2.

Method 1
On the computer that is running the CA service, make sure that the Certificate Services service is running. If the service is not running, start the service.

To start the Certificate Services service, follow these steps:
 * 1) Click Start, click Run, type services.msc, and then click OK.
 * 2) In the Services pane, right-click Certificate Services, and then click Start.

When you have completed these steps, try to access OWA by using SSL.

Method 2
On the Web server, remove the current SSL server certificate for the Default Web site, and then create a new SSL server certificate request.

Remove the current SSL server certificate

 * 1) Start Internet Services Manager (ISM). ISM starts the Microsoft Internet Information Services (IIS) snap-in for Microsoft Management Console (MMC).
 * 2) Select the Default Web site, right-click the site, and then click Properties.
 * 3) In the Properties dialog box, click the Directory Security tab, and then click Server Certificate. The Web Site Certificate Wizard opens.
 * 4) In the Web Site Certificate Wizard, click Next.
 * 5) Click Remove the Current Certificate, and then click OK.
 * 6) Verify that the certificate name that appears is the name of the server certificate that you want to remove. Click Next.
 * 7) Click Finish.

Note By removing the server certificate from the Web site, you only disable the secure communications (SSL/TLS) on that site. The server certificate will still exist in the Certificate Store of the server. Therefore, you can still assign the server certificate to the Web site again if the server certificate is required. If you are sure that you will not assign the server certificate to the Web site again, you may also remove the server certificate from the Certificate Store.
 * 1) Right-click the computer name in MMC, and then click Restart IIS.

Create a new SSL server certificate request
When you create a new SSL server certificate request on the Web server, select the Prepare the request now, but send it later option. To do this, follow these steps:
 * 1) Start the ISM. ISM starts the IIS snap-in for MMC.
 * 2) In the Interface pane, right-click the Web site for which you want to add the certificate, and then click Properties.
 * 3) In the Properties dialog box, click the Directory Security tab, and then click Server Certificate to start the Web Server Certificate Wizard. In the wizard, click Next.
 * 4) Select Create a new certificate, and then click Next.
 * 5) Select Prepare the request now, but send it later, and then click Next.
 * 6) Type a name for the certificate.
 * 7) Select the bit length of the key that you want to use, specify whether you want to use Server Gated Cryptography (SGC), and then click Next.

Note For more information about bit length and SGC, see the IIS Help file on the Web server.
 * 1) In the Organization and Organizational Unit box, type the name of your organization and organizational unit, and then click Next.
 * 2) In the Interface pane, type the common name for your site, and then click Next.

Note The common name must match the fully qualified domain name (FQDN) of the server as the FQDN is listed in DNS. For example, the following URL and common name match:
 * 1) * URL: https://www.contoso.com/securedir
 * 2) * Common name: www.contoso.com
 * 3) In the Country box, type your country. In the State box, type your state.

Note You must type the full name of your state instead of the abbreviation. In the City or Locality box, type your city or locality.

Click Next.
 * 1) Select a location to which you want to save your request, type a file name, and then click Next.
 * 2) Click Next, and then click Finish to close the wizard.

Restart the Certificate Services service
To restart the service, follow these steps:
 * 1) Click Start, click Run, type services.msc, and then click OK.
 * 2) In the Services pane, right-click Certificate Services, and then click Start.

When you have completed these steps, try to access OWA by using SSL.



STATUS
Microsoft has confirmed that this is a bug in the Microsoft products that are listed in the &quot;Applies to&quot; section.

Keywords: kbbug kbexpertiseinter kberrmsg kbtshoot KB922423

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.