Windows Vista Forums

leaf certificate
  1. #1


    Ingmar Van Glabbeek Guest

    leaf certificate

    When working with a self signed certificate, how do I make a new leaf
    for webmail.foo.bar?



      My System SpecsSystem Spec

  2. #2


    Ingmar Van Glabbeek Guest

    Re: leaf certificate

    To clarify, this is on a SBS2008 server

    Op 19/03/2010 10:22, Ingmar Van Glabbeek schreef:

    > When working with a self signed certificate, how do I make a new leaf
    > for webmail.foo.bar?

      My System SpecsSystem Spec

  3. #3


    Cliff Galiher - MVP Guest

    Re: leaf certificate

    You don't. Self-signed, by definition, isn't capable of being in a chain.

    You *can*, however, issue certificates from an internal CA. These aren't
    "self-signed" but are "self-issued." They are signed by your internal CA
    server so they won't be trusted by non-domain machines...so they'd behave
    very similar to self-signed certificates.

    In SBS 2003, you'd have to install the CA role and configure it. Technet
    has several articles on this process.
    In SBS 2008, the CA role is installed by default, so you'd use the
    certificate MMC snap-ins to request and issue certificates.

    -Cliff



    "Ingmar Van Glabbeek" <ingmar.vg@newsgroup> wrote in message
    news:OTua3W0xKHA.3408@newsgroup

    > When working with a self signed certificate, how do I make a new leaf for
    > webmail.foo.bar?

      My System SpecsSystem Spec

  4. #4


    Ingmar Van Glabbeek Guest

    Re: leaf certificate

    With the MMC module in sbs2008 I manage to enroll a new cert for my
    server but I can't see where I could issue another one for a different URL.



    Op 20/03/2010 18:51, Cliff Galiher - MVP schreef:

    > You don't. Self-signed, by definition, isn't capable of being in a chain.
    >
    > You *can*, however, issue certificates from an internal CA. These aren't
    > "self-signed" but are "self-issued." They are signed by your internal CA
    > server so they won't be trusted by non-domain machines...so they'd
    > behave very similar to self-signed certificates.
    >
    > In SBS 2003, you'd have to install the CA role and configure it. Technet
    > has several articles on this process.
    > In SBS 2008, the CA role is installed by default, so you'd use the
    > certificate MMC snap-ins to request and issue certificates.
    >
    > -Cliff
    >
    >
    >
    > "Ingmar Van Glabbeek" <ingmar.vg@newsgroup> wrote in message
    > news:OTua3W0xKHA.3408@newsgroup

    >> When working with a self signed certificate, how do I make a new leaf
    >> for webmail.foo.bar?
    >

      My System SpecsSystem Spec

  5. #5


    Cliff Galiher - MVP Guest

    Re: leaf certificate

    If this is for a web server (such as IIS) which it sounds like based on your
    comments, you'll need to use the IIS snap-in to generate a CSR. You can
    then either issue the certificate manually with the CSR generated, or you
    can issue the certificate automatically as part of the CSR wizard.

    Once you get into the IIS certificate wizard, it'll become a lot more clear
    and self-explanatory.

    -Cliff


    "Ingmar Van Glabbeek" <ingmar.vg@newsgroup> wrote in message
    news:#30bHebyKHA.1796@newsgroup

    > With the MMC module in sbs2008 I manage to enroll a new cert for my server
    > but I can't see where I could issue another one for a different URL.
    >
    >
    >
    > Op 20/03/2010 18:51, Cliff Galiher - MVP schreef:

    >> You don't. Self-signed, by definition, isn't capable of being in a
    >> chain.
    >>
    >> You *can*, however, issue certificates from an internal CA. These aren't
    >> "self-signed" but are "self-issued." They are signed by your internal CA
    >> server so they won't be trusted by non-domain machines...so they'd
    >> behave very similar to self-signed certificates.
    >>
    >> In SBS 2003, you'd have to install the CA role and configure it. Technet
    >> has several articles on this process.
    >> In SBS 2008, the CA role is installed by default, so you'd use the
    >> certificate MMC snap-ins to request and issue certificates.
    >>
    >> -Cliff
    >>
    >>
    >>
    >> "Ingmar Van Glabbeek" <ingmar.vg@newsgroup> wrote in message
    >> news:OTua3W0xKHA.3408@newsgroup

    >>> When working with a self signed certificate, how do I make a new leaf
    >>> for webmail.foo.bar?
    >>
    >

      My System SpecsSystem Spec

leaf certificate problems?

Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista Leaf Water Drop DreamScene Deckz Vista General 2 10 Apr 2010
Copy-Item : Container cannot be copied onto existing leaf item. Steve PowerShell 3 17 Mar 2009
Leaf network?? adeang Network & Sharing 2 22 Sep 2008
Select Certificate message, but no certificate to select MikeS Vista security 1 16 Feb 2008
tabcompletion does not show : Split-Path -Leaf /\\/\\o\\/\\/ [MVP] PowerShell 4 11 Oct 2006