Microsoft KB Archive/272555

= Certificate Services in a Non-Active Directory Environment: Installation and Issuing Certificates =

Article ID: 272555

Article Last Modified on 2/28/2007

-

APPLIES TO


 * Microsoft Windows 2000 Server
 * Microsoft Windows 2000 Advanced Server

-



This article was previously published under Q272555





IN THIS TASK

 * SUMMARY
 * Install the Certificate Server
 * Create an MMC Snap-in to Administer the Certificate Server
 * Create a Certificate Request for an IIS Web Site
 * Submit the Certificate Request Using Certificate Services
 * Approve the Certificate Request
 * Download and Install the Certificate
 * Request a Client Certificate
 * Approve the Client Certificate
 * Install the Certificate on the Client Computer
 * REFERENCES



SUMMARY
This step-by-step article describes how to install and configure a Certificate Server in a non-Active Directory environment. It includes step-by-step instructions for installing the server and client certificates.

back to the top

Install the Certificate Server
To install a Certificate Server on your Windows 2000 server:
 * 1) Click Start, point to Settings and then click Control Panel.
 * 2) In Control Panel, double-click Add/Remove Programs.
 * 3) Click Add/Remove Windows Components to start the Windows Component Wizard.
 * 4) In the Windows Component Wizard, click to select theCertificate Services check box.
 * 5) Click Yes to confirm that this computer can no longer be renamed and cannot change domain membership.
 * 6) Click Next.
 * 7) Click Remote administration mode, and then click Next.
 * 8) Click Stand-alone root CA, and then click Next.
 * 9) Type the CA name for your organization, type any additional information you may require, and then click Next.
 * 10) Click Next.
 * 11) Click OK to stop the Internet Information services.

Note You may be prompted for your Windows 2000 CD-ROM.
 * 1) When the Windows Components Wizard has completed, click Finish.

back to the top

Create an MMC Snap-in to Administer the Certificate Server
To add the Microsoft Management Console (MMC) snap-in to administer Certificate Services:
 * 1) Click Start, and then click Run.
 * 2) In the Open box, type MMC, and then press ENTER.
 * 3) On the Console menu, click Add/Remove Snap-in.
 * 4) Click Add.
 * 5) In the Add Standalone Snap-in dialog box, click Certification Authority, and then click Add.
 * 6) Click Local computer, and then click Finish.
 * 7) Click Close.
 * 8) Click OK.
 * 9) Click Console, and then click Save As.
 * 10) Type a name, and then click Save.

back to the top

Create a Certificate Request for an IIS Web Site
To request a Web site certificate from the Certificate Services Server:
 * 1) Start Internet Services Manager.
 * 2) Double-click your IIS Server.
 * 3) Right-click the Web site where you want to install the certificate, and then click Properties.
 * 4) Click Directory Security.
 * 5) Click Server Certificate to start the Web Server Certificate Wizard.
 * 6) Click Next.
 * 7) Click Create a new certificate, and then click Next.
 * 8) Click Next.
 * 9) Type a name for the certificate, and then click Next.
 * 10) Type your organization name and organizational unit, and then click Next.
 * 11) In the Common name box, type a name for your site by using your computer DNS or NetBIOS name, and then click Next.
 * 12) Complete the Geographical Information page, and then click Next.
 * 13) Leave the default name for the certificate request, note the name and location of this file, and then click Next.
 * 14) Click Next.
 * 15) Click Finish.
 * 16) Click OK.

back to the top

Submit the Certificate Request Using Certificate Services
To submit the certificate request that you created in the previous procedure you must submit it to Certificate Services. Certificate Services then issues a certificate that you can install on your Web site. To do this:  Start Microsoft Internet Explorer, and then locate the following URL

http://CertificateServerComputerName/certsrv

where  is the name of your Certificate Services server. Click Request a Certificate, and then click Next. Click Advanced Request, and then click Next. Click Submit a certificate request using a base64 encoded PKCS #10 file or a renewal request using a base64 encoded PKCS #7 file, and then click Next.  Put the contents of the certificate request file that you created in the previous procedure on the Submit A Saved Requests page. Only put the text that appears between the following two lines: -BEGIN NEW CERTIFICATE REQUEST-

-END NEW CERTIFICATE REQUEST-

Note Do not include the BEGIN and END lines. Only use the text that appears between them.  Click Submit.</li> The Certificate Pending page appears and states:

Your certificate request has been received. However, you must wait for an administrator to issue the certificate you requested. Please return to this web site in a day or two to retrieve your certificate.

Note: You must return with this web browser within 10 days to retrieve your certificate

Your certificate request has been submitted.

</li></ol>

back to the top

Approve the Certificate Request
To approve the certificate request, you must manually approve the request by using the Certificate Services MMC that you previously created:
 * 1) Start the Certificate Services console that you created in the &quot;Create an MMC Snap-in to Administer the Certificate Server&quot; section of this article.
 * 2) Double-click Certification Authority (local), and then double-click your server.
 * 3) In the right pane, double-click Pending Requests.
 * 4) In the right pane, right-click the request, point to All Tasks, and then click Issue.

back to the top

Download and Install the Certificate
To install the approved certificate, you must first download it from Certificate Services and then install it on your computer: <ol> Start Internet Explorer, and then locate the following URL

http://CertificateServerComputerName/certsrv

where  is the name of your Certificate Services server.</li> Click Check on pending certificate, and then click Next.</li> Click the request you submitted, and then click Next.</li> Click Download CA certificate.</li> In the File Download dialog box, click Save this file to disk, and then click OK.</li> Specify the location to save the file, and then click Save.</li> Click Open.</li> In the Certificate dialog box, click Install Certificate to start the Certificate Import Wizard.</li> Click Next.</li> Click Automatically select the certificate store based on the type of certificate, and then click Next</li> Click Finish.</li> Click OK to confirm the import.</li> Click OK.</li></ol>

back to the top

Request a Client Certificate
To request a client certificate: <ol> Start Internet Explorer, and then locate the following URL

http://CertificateServerComputerName/certsrv

where  is the name of your Certificate Services server.</li> <li>Click Request a Certificate, and then click Next.</li> <li>Click Web Browser Certificate, and then click Next.</li> <li>Complete the Identifying Information boxes, and then click Submit.

Note Required fields can be determined by the Certificate Services administrator.</li> <li>The Certificate Pending page appears and states:

Your certificate request has been received. However, you must wait for an administrator to issue the certificate you requested. Please return to this web site in a day or two to retrieve your certificate.

Note: You must return with this web browser within 10 days to retrieve your certificate

Your certificate request has been submitted.

</li></ol>

back to the top

Approve the Client Certificate
To approve the client certificate request:
 * 1) Start the Certificate Services console that you created in the &quot;Create an MMC Snap-in to Administer the Certificate Server&quot; section of this article.
 * 2) Double-click Certification Authority (local), and then double-click your server.
 * 3) In the right pane, double-click Pending Requests.
 * 4) In the right pane, right-click the request, point to All Tasks, and then click Issue.

back to the top

Install the Certificate on the Client Computer
To install the client certificate: <ol> <li>Start Internet Explorer, and then locate the following URL

http://CertificateServerComputerName/certsrv

where  is the name of your Certificate Services server.</li> <li>Click Check on pending certificate, and then click Next.</li> <li>Click the request that you submitted, and then click Next.</li> <li>Click Install this certificate.</li> <li>The Certificate Installed page appears and states:

Your new certificate has been successfully installed.

</li></ol>

back to the top

<div class="references_section">