Windows 10: CA Intermediate certificate deployment in organization

Discus and support CA Intermediate certificate deployment in organization in Windows 10 Software and Apps to solve the problem; Hi,what is the best practices for intermediate certificate renewal and deployment with the same key pair.required to deploy renewed intermediate... Discussion in 'Windows 10 Software and Apps' started by ManinderSingh1007, Dec 1, 2022.

  1. CA Intermediate certificate deployment in organization


    Hi,what is the best practices for intermediate certificate renewal and deployment with the same key pair.required to deploy renewed intermediate certificate in organization before to install them on Issuing CA.may it correct to add new AIA location before to install on issuing CA.is it required to remove old certificate AIA location after install certificat on Issuing CA.@Maninder Singh

    :)
     
    ManinderSingh1007, Dec 1, 2022
    #1

  2. 6680 CA certificates

    The CA certificate for SSL connections that I use is untrusted by the phone. How do I add the CA to the list of existing trusted certificates?
     
    hiltonian---01, Dec 1, 2022
    #2
  3. a14karat Win User
    Web Client Authentication via SSL Certificate

    Yes, the certificate has been loaded as a personal certificate.

    We typically only use a CA and a client - no intermediate.

    When I first installed the certificates, the CA cert was ok, but the client cert installed as an intermediate.

    Last night I figured out that if I produce the CA and client as a pfx, the pfx will install the certs correctly - CA and Personal (with no intermediate)

    My last ditch effort will be to go back and produce a CA - Intermediate - Client chain, but was really hoping I wouldn't have to do that because it will really require a complete redo of all of our certificates across the board...

    Here is more detail of what's going on (just example - no secure info given here)...

    Three SSLRequire parameters are validated by Apache as follows:

    SSLRequire %{SSL_CLIENT_S_DN_O} eq "Our Organization"

    SSLRequire %{SSL_CLIENT_S_DN_CN} eq "User Division Level"

    SSLRequire %{SSL_CLIENT_S_DN_OU} eq "User Level"

    The only parameter that Apache is able to validate from the device is DN_O and that is coming from the CA certificate.

    DN_CN & DN_OU are contained in the user certificate but it is not able to validate those.
     
    a14karat, Dec 1, 2022
    #3
  4. CA Intermediate certificate deployment in organization

    Go Daddy's intermediate CA certificate missing

    An unaffected PC (Windows 10 Pro connected to AD DS domain)


    CA Intermediate certificate deployment in organization R9BrZ.png


    CA Intermediate certificate deployment in organization Qp132.png




    Affected PCs (Windows 10 Pro standalones)


    CA Intermediate certificate deployment in organization ZwhLz.png


    CA Intermediate certificate deployment in organization UmtWF.png


    CA Intermediate certificate deployment in organization tqwhV.png




    What could cause intermediate but not root CA certificates to be missing?

    I've verified that local policy Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings\Turn off Automatic Root Certificates Update isn't configured.

    I've verified that Windows service Cryptographic Services / CryptSvc is running and restarting it didn't make a difference.

    I've found that no relevant events are logged, as far as I can see.

    Support for urgent Trusted Root updates for Windows Root Certificate Program in Windows - Microsoft Support says:

    How do you manually force an update?
     
    mythofechelon, Dec 1, 2022
    #4
Thema:

CA Intermediate certificate deployment in organization

Loading...
  1. CA Intermediate certificate deployment in organization - Similar Threads - Intermediate certificate deployment

  2. accidentally deleted the CA certificate template

    in Windows 10 Gaming
    accidentally deleted the CA certificate template: Hi,When I was working on a certificate issue, I accidentally deleted a certificate template. This template is used by all windows servers and dcs. As I am still new to CA infrastructure and my senior who set up this is not available, I do not know what's the consequences...
  3. accidentally deleted the CA certificate template

    in Windows 10 Software and Apps
    accidentally deleted the CA certificate template: Hi,When I was working on a certificate issue, I accidentally deleted a certificate template. This template is used by all windows servers and dcs. As I am still new to CA infrastructure and my senior who set up this is not available, I do not know what's the consequences...
  4. CA Intermediate certificate deployment in organization

    in Windows 10 Gaming
    CA Intermediate certificate deployment in organization: Hi,what is the best practices for intermediate certificate renewal and deployment with the same key pair.required to deploy renewed intermediate certificate in organization before to install them on Issuing CA.may it correct to add new AIA location before to install on...
  5. Weird certificate XBL Client IPsec Issuing CA found in my certificate store

    in Windows 10 Software and Apps
    Weird certificate XBL Client IPsec Issuing CA found in my certificate store: I noticed some errors in my event viewer telling me a certificate with a specific thumbprint could not be renewed. I went to find which certificate it was and it was found under local computer/personal certificates and it was issued by XBL Client IPsec Issuing CA. After...
  6. Weird certificate XBL Client IPsec Issuing CA found in my certificate store

    in Windows 10 Customization
    Weird certificate XBL Client IPsec Issuing CA found in my certificate store: I noticed some errors in my event viewer telling me a certificate with a specific thumbprint could not be renewed. I went to find which certificate it was and it was found under local computer/personal certificates and it was issued by XBL Client IPsec Issuing CA. After...
  7. The Certificate Delivered by CA means nothing. Here are the proofs

    in AntiVirus, Firewalls and System Security
    The Certificate Delivered by CA means nothing. Here are the proofs: I got a Certificate for my app.Took me a week to get it! The authority who issued the certificate are not to be trusted.First they are a security risk and leak your personal information.They gave out my personal information to anyone who would simply log on to the support...
  8. SCEP deployment to Windows 10 devices fails after you renew the CA certificate

    in Windows 10 News
    SCEP deployment to Windows 10 devices fails after you renew the CA certificate: [ATTACH]SCEP or Simple Certificate Enrollment Protocol, is a protocol that allows devices to enroll for a certificate using a URL and a secret key. On […] This article SCEP deployment to Windows 10 devices fails after you renew the CA certificate first appeared on...
  9. Creating Personal Certification Authority CA for VPN service

    in AntiVirus, Firewalls and System Security
    Creating Personal Certification Authority CA for VPN service: Hello Not sure if this is the right 'forum' to post this but MS does have it's own well built in VPN GUI now so? The main question is what would the community recommend or say is the best application/program/software for creating Digital key pairs for encrypting a...
  10. Creating Personal Certification Authority CA for VPN service

    in AntiVirus, Firewalls and System Security
    Creating Personal Certification Authority CA for VPN service: Hello Not sure if this is the right 'forum' to post this but MS does have it's own well built in VPN GUI now so? The main question is what would the community recommend or say is the best application/program/software for creating Digital key pairs for encrypting a...