<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Security</title><link>http://forums.iis.net/1031.aspx</link><description>A forum aimed at helping understand IIS security such as Authentication, IP restrictions, and SSL</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889682.aspx</link><pubDate>Mon, 12 Jan 2009 14:09:27 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889682</guid><dc:creator>qbernard</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889682.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889682</wfw:commentRss><description>&lt;p&gt;Wow.. that was tough!&lt;/p&gt;
&lt;p&gt;Thanks for the update.&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889644.aspx</link><pubDate>Mon, 12 Jan 2009 05:15:46 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889644</guid><dc:creator>ganeshanekar</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889644.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889644</wfw:commentRss><description>&lt;strong&gt;To benifit other users, posting what we did on this:&lt;br /&gt;&lt;/strong&gt;&lt;font size="1"&gt;&lt;br /&gt;&lt;font size="2"&gt;We worked on this offline and looked at the configuration of SSL. (Server Windows 2000 SP4 - IIS 5.0).&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;font size="2"&gt;The actual error we’re seeing in the SSL Diagnostics tool is, &amp;quot;You have a private key that corresponds to this certificate but &lt;strong&gt;CryptAcquireCertificatePrivateKey&lt;/strong&gt; failed.&amp;quot; &lt;/font&gt;&lt;/font&gt;&lt;font size="1"&gt;
&lt;p&gt;&lt;font size="2"&gt;This almost always means there’s a permissions problem accessing the private key, which is stored in the MachineKeys directory. We checked and verified the permissions and ensured that all machine keys prems are good (KB278381), but it still didn&amp;#39;t work.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;We checked the certificate which was sent by Verisign - It was in p7b format?? - It shows it has private key - but does not allow the export private key. From IIS certificate Wizard, everytime we tried to complete pending request with certificate that was sent by verisign - We see &amp;quot;Keyset does not exist&amp;quot; error.&lt;br /&gt;&lt;br /&gt;Test certificate from SSLDiag - Works fine no issues with that at all. Issue seems to be with Verisign certificate but does not have enough evidance.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;Finally after some troubleshooting instead of finding out the root cause - We concluded to take a back up of IIS metabase and re-install IIS as there are only few sites running on this box. &lt;/font&gt;&lt;font size="2"&gt;Stam to take a call on re-installing IIS.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font size="2"&gt;~ Ganesh&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889213.aspx</link><pubDate>Wed, 07 Jan 2009 02:07:56 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889213</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889213.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889213</wfw:commentRss><description>&lt;p&gt;And now what should I do to solve the problem?&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889211.aspx</link><pubDate>Wed, 07 Jan 2009 01:58:00 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889211</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889211.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889211</wfw:commentRss><description>&lt;p&gt;Mr. Ganeshanekar, I have sent you a email already. Thanks for your help!&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889110.aspx</link><pubDate>Tue, 06 Jan 2009 08:15:38 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889110</guid><dc:creator>ganeshanekar</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889110.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889110</wfw:commentRss><description>&lt;p&gt;&lt;a href="mailto:ganeshanekar@hotmail.com"&gt;ganeshanekar@hotmail.com&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889109.aspx</link><pubDate>Tue, 06 Jan 2009 07:57:28 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889109</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889109.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889109</wfw:commentRss><description>&lt;p&gt;When I copied the certificate from Verisign&amp;#39;s email to notepad and save as &amp;quot;.cer&amp;quot; file, it cannot be viewed after I double click it. It only&amp;nbsp;pops up a mesasge: &amp;quot;this is an invalid security certificate file&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Verisign told me to save it as &amp;quot;.p7b&amp;quot; and I can open it by double click. But when I process the pending request using the &amp;quot;.p7b&amp;quot; certificate, it still failed and get the same error messge &amp;quot;Keyset does not exists&amp;quot;.&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889108.aspx</link><pubDate>Tue, 06 Jan 2009 07:32:41 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889108</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889108.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889108</wfw:commentRss><description>&lt;p&gt;I don&amp;#39;t know why the private key of the pending CSR cannot be backup. That is, it does not allow me to export the private key, in MMC program. Verisign said that&amp;nbsp;I should edit the permission of the container folder to allow administrator account and system account full control. but it doesn&amp;#39;t help. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;And the main problem is I don&amp;#39;t know why the certificate from verisign cannot be installed in my web server. always saying &amp;quot;keyset does not exist&amp;quot;.&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889107.aspx</link><pubDate>Tue, 06 Jan 2009 07:18:26 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889107</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889107.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889107</wfw:commentRss><description>&lt;p&gt;What is your email ganeshanekar, because I don&amp;#39;t know how to insert image using this forum&amp;#39;s email.&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889106.aspx</link><pubDate>Tue, 06 Jan 2009 07:09:48 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889106</guid><dc:creator>ganeshanekar</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889106.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889106</wfw:commentRss><description>&lt;p&gt;That&amp;#39;s Good News!&lt;/p&gt;
&lt;p&gt;Can you send me screen shot of the website certificate (certification path tab)? (send me private message or email).&lt;/p&gt;
&lt;p&gt;~ Ganesh&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889105.aspx</link><pubDate>Tue, 06 Jan 2009 06:57:34 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889105</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889105.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889105</wfw:commentRss><description>&lt;p&gt;I installed the root certificate successfully. And now it is the same as before. Only showing my current certificate is expired.&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889097.aspx</link><pubDate>Tue, 06 Jan 2009 04:46:02 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889097</guid><dc:creator>ganeshanekar</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889097.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889097</wfw:commentRss><description>&lt;p&gt;Can you send me screen shot of the website certificate (certification path tab)?&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889096.aspx</link><pubDate>Tue, 06 Jan 2009 04:32:21 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889096</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889096.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889096</wfw:commentRss><description>&lt;p&gt;I tried to search but it doesn&amp;#39;t have tutorial on how&amp;nbsp;to download and install the Verisign Root certificate. Is it easy to download and install? And how?&lt;/p&gt;Oh, 1 found it. Let me try...</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889093.aspx</link><pubDate>Tue, 06 Jan 2009 01:55:29 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889093</guid><dc:creator>stamtarm</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889093.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889093</wfw:commentRss><description>&lt;p&gt;Ok, i try to install the Verisign Root CA.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;And there is a security concern if I allow Ganeshanekar to access my company&amp;#39;s web server... &lt;/p&gt;
&lt;p&gt;Actually every thing working fine before. As I knew the&amp;nbsp;certificate installed in the web server going to be expired in 20/12/2008, I renew the certificate via Verisign on 12/12/2008 and tried to install the new certificate into the web server. It failed. Afterthat, I revoke the new certificate and replace it by requesting another certificate. But still failed. Then I edit the permission of the container folders and requseted new certificate again and the installation failed again. I issued 8 certificates from Verisign already by revoke and replace.&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889017.aspx</link><pubDate>Mon, 05 Jan 2009 11:12:55 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889017</guid><dc:creator>ganeshanekar</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889017.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889017</wfw:commentRss><description>&lt;p&gt;Can you provide me access to server, I will walk you through the steps.&lt;/p&gt;
&lt;p&gt;~ Ganesh&lt;/p&gt;</description></item><item><title>Re: Failed to install Verisign SSL digital certificate on IIS 5.0. Please help!!</title><link>http://forums.iis.net/thread/1889016.aspx</link><pubDate>Mon, 05 Jan 2009 11:08:41 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1889016</guid><dc:creator>Paul Lynch</dc:creator><slash:comments>0</slash:comments><comments>http://forums.iis.net/thread/1889016.aspx</comments><wfw:commentRss>http://forums.iis.net/commentrss.aspx?SectionID=1031&amp;PostID=1889016</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;Was your previous web site certificate working properly without any errors until recently ? If so then I don&amp;#39;t think there was a problem with either your Verisign Root or Intermediate certificates.&lt;/p&gt;&lt;p&gt;It sounds to me as though you have followed the instructions at the URL provided previously&amp;nbsp; (https://knowledge.verisign.com/support/ssl-certificates-support/index?page=content&amp;amp;id=S:SO7094) but you have put the Verisign Intermediate certificate in your machine&amp;#39;s Root certificate store.&lt;/p&gt;&lt;p&gt;If that is the case you will need to download the Verisign Root CA and place it in your machine&amp;#39;s root store and then do the same for the Verisign Intermediate CA and place that in your machine&amp;#39;s Intermediate cert store.&lt;/p&gt;&lt;p&gt;Regards,&amp;nbsp;&lt;/p&gt;</description></item></channel></rss>