Microsoft KB Archive/928146

= How to create and to import certificates for use by Groove Data Bridge Server 2007 =

Article ID: 928146

Article Last Modified on 12/11/2006

-

APPLIES TO


 * Microsoft Office Groove Server 2007 Data Bridge

-



INTRODUCTION
This article describes how to create and to import certificates for use by Microsoft Office Groove Data Bridge Server 2007.



How to create a certification authority on a computer that is running Microsoft Windows Server 2003
 Click Start, click Run, type appwiz.cpl, and then click OK. Click Add/Remove Windows Components. Click Certificate Services. You receive the following message:

After you install Certificate Services, the computer name and domain membership may not be changed due to the binding of the machine name to CA information stored in the Active Directory. Changing the machine name of domain membership would invalidate the certificates issued from the CA. Please ensure the proper machine name and domain membership are configured before installing Certificate Services. Do you want to continue?

 If you are sure that the computer name and the domain membership do not have to be changed, click Yes, and then click Next. Click Stand-alone root CA, and then click Next. Enter the information in the Common name for this CA field and in the Validity period field, and then click Next. Enter locations for the certificate database, the database log, and the configuration information, and then click Next.

Alternatively, click Next to accept the default values.</li> Click Yes when you receive the following message:

To complete the installation, Certificate Services must temporarily stop Internet Information Services. Do you want to stop the service now?

</li> When you are prompted for the Windows Server 2003 installation files, provide a source for the files to complete the installation.</li> Click Finish.</li></ol>

<div class="moreinformation_section">

How to use the certificates on the server that is running Data Bridge Server 2007
<ol> Download and then import a certification authority certificate to the Data Bridge Server 2007 server. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> In Internet Explorer, visit the following Web site:

http:// /certserv

Do this to connect to Active Directory Certificate Services on the computer on which you configured Certificate Services.</li> Click Download a CA certificate, certificate chain or CRL.</li> Open the certificate, and then click Install certificate.</li> Click Next.</li> Click Place all certificates in the following store, and then click Browse.</li> Click Show physical stores, expand Trusted Root Certification Authorities, click Local Computer, and then click OK.</li> Click Next, and then click Finish.</li></ol> </li> Request a certificate to export to the Data Bridge Server 2007 server. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> In Internet Explorer, visit the following Web site:

http:// /certserv

Do this to connect to Active Directory Certificate Services on the computer on which you configured Certificate Services.</li> Click Request a certificate.</li> Click advanced certificate request, and then create a request to this certification authority by clicking to select the following check boxes: <ul> Mark keys as exportable</li> <li>Enable strong private key protection</li></ul> </li> <li>Click Yes when you receive the following message:

Do you want to request a certificate now?

</li> <li>Click OK.</li> <li>On the Certificate Issued page, click Install this certificate.</li> <li>In Internet Explorer, click Internet Options on the Tools menu, and then click the Content tab.</li> <li>Under Certificates, click Certificates, locate and then click the certificate that you installed, and then click Export.</li> <li>In the Certificate Export Wizard, click Yes, export the private key, and then click Next.</li> <li>Create a name for the file. You may want to use the same name as the certificate name. The certificate name must match the member name that you will create later in Groove Management Server. Additionally, when you use the same name for the file, the file will be easier to associate with the correct certificate.

Accept the defaults for other values.</li> <li>Click OK. The exported certificate appears on the desktop. To use the certificate, you must import it to the Data Bridge Server 2007 server. To do this, go to step 3.</li></ol> </li> <li>Import the certificate to the Data Bridge Server 2007 server. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> <li>Start Microsoft Management Console.</li> <li>On the File menu, click Add/Remove Snap-in.</li> <li>Click Add.</li> <li>In the Add Standalone Snap-ins dialog box, click Certificates, and then click Add.</li> <li>Click Computer account, and then click Next.</li> <li>Click Local Computer, and then click Finish.</li> <li>Click OK, and then click Close.</li> <li>From Console Root, expand Certificates (Local Computer), right-click Personal, point to All tasks, and then click Import.</li> <li>Click Next.</li> <li>Click Browse, locate and then click the certificate, and then click Open.</li> <li>Click Next.</li> <li>Click Place all certificates in the following store, click Browse, click Personal, and then click Next.</li> <li>Click Finish.

Note After you have successfully exported and imported the certificate, you can remove the certificate. To do this, follow these steps: <ol> <li>In Internet Explorer, click Internet Options on the Tools menu.</li> <li>Click the Content tab, and then click Certificates.</li> <li>Select the certificate that you want to remove, and then click Remove.</li></ol> </li></ol> </li> <li>Create a managed Groove domain identity that can run Data Bridge Server 2007 as a service. To do this, follow these steps: <ol style="list-style-type: lower-alpha;"> <li>In Internet Explorer, visit the following Web site:

http:// /gms

Do this to connect to the Groove Management Server.</li> <li>Expand the Groove domain that will use the certificate.</li> <li>In the domain, click Members.</li> <li>On the Members tab, click Add Members.</li> <li>Click Add Single Member, and then click Next.</li> <li>In the Select Member Settings dialog box, click Next.</li> <li>In the Add Single Member dialog box, enter the required information, and then click Finish to create the member.

Note You may want to use an administrative address for the e-mail address so that workspace managers can obtain a point of contact from the member properties.

Data Bridge Server 2007 can now run as a service.</li></ol> </li></ol>

Keywords: kbexpertiseadvanced kbhowto KB928146

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.