How to use Microsoft Certificate Authority

What is Microsoft Certificate Authority Server?

Microsoft Certificate Authority (CA) is part of the Windows Server operating system. A certification authority (CA) is responsible for attesting to the identity of users, computers, and organizations. The CA authenticates an entity and vouches for that identity by issuing a digitally signed certificate. The CA can also manage, revoke, and renew certificates.

Whenever a user requests to access a virtual environment, the front end servers contact the Federated Authentication Service (FAS) in the environment. The FAS, in conjunction with Microsoft Certification Authority, grants a ticket that allows a single session to authenticate with a certificate for that session.

10/14/2021 791 People found this article helpful

How to use Microsoft Certificate Authority
259,802 Views

Description

This article describes how to obtain a certificate from an internal CA for the purpose of SonicWall Web Management.

Deployment Prerequisites

  • Microsoft Windows Active Directory Services installed and configured.
  • Microsoft Certificate Services installed and configured.
  • Microsoft Internet Information Services (IIS) 7.0 installed and configure.

Deployment Steps

  1.  Exporting the CA Certificate from the Active Directory Server.
  2. Importing the CA Certificate onto the SonicWall.
  3. Creating a New Signing Request in SonicWall Appliance.
  4. Requesting certificate for the new signing Request by the MS Certificate Authority.
  5. Validating the Certificate on the SonicWall Appliance.
  6. How to Test

Resolution

Exporting the Root CA Certificate from the Active Directory (AD) Server
  1. In the AD server, launch the Certificate Authority application by Start | Run | certsrv.msc.
  2. Right click the CA you created and select Properties.
  3. On the General tab, click View Certificate button.
  4. On the Details tab, select Copy to File.
  5. Follow through the wizard, and select the DER Encoded binary X.509 (.cer) format.
  6. Click browse and specify a path and filename to save the certificate.
  7. Click  Next button and click Finish.
    How to use Microsoft Certificate Authority

     
    How to use Microsoft Certificate Authority
    How to use Microsoft Certificate Authority

     
    How to use Microsoft Certificate Authority
    How to use Microsoft Certificate Authority

     
    How to use Microsoft Certificate Authority
    How to use Microsoft Certificate Authority

     
    How to use Microsoft Certificate Authority
    How to use Microsoft Certificate Authority

 Importing the CA Certificate onto the SonicWall
  1. Click Manage in the top navigation menu.
  2. Navigate to Appliance | Certificates.
    How to use Microsoft Certificate Authority
  3. Click Import. Select the certificate file you just exported.
    How to use Microsoft Certificate Authority
  4. Select Import a CA certificate from a PKCS#7 (.p7b), PEM (.pem) or DER (.der or .cer) encoded file, 
  5. Click Browse and Select the certificate file you just exported from the MS Certificate Authority.
  6. Once the root certificate is selected, Click  import button.
    How to use Microsoft Certificate Authority

  7. Once the CA root certificate is imported, it will be listed under the Appliance | Certificates page with type as CA Certificate.

    How to use Microsoft Certificate Authority
    TIP: This page can be filtered to easily locate this certificate by changing the View Style to Imported certificates and requests. 

    How to use Microsoft Certificate Authority

 Creating a Certificate Signing Request (CSR) in SonicWall Appliance
  1. Navigate to Appliance | Certificates page and click New Signing Request.
  2. Fill out the CSR form in SonicWall device and click  Generate. For the most part, you can leave the drop-down boxes to their defaults and fill out each field as suggested by its corresponding drop-down box.
    How to use Microsoft Certificate Authority
  3.  The Appliance | Certificates page will refresh and your new certificate will appear with a type of Pending Request.

    How to use Microsoft Certificate Authority
    NOTE: You may need to refresh the page for this status to appear.

    How to use Microsoft Certificate Authority
  4. Click  Export
    How to use Microsoft Certificate Authority
     button.  In the new Pop-up window, click Export and save the file locally on your device for later import to the Windows Server.
    How to use Microsoft Certificate Authority

 Requesting a certificate for the CSR from the MS Certificate Authority

How to use Microsoft Certificate Authority
TIP: If the MS CA server is running IIS (and the admin has allowed access to this interface), the easiest way to submit the firewall s CSR is via web browser.

  1. Open a browser and enter  http://x.x.x.x/certsrv/  (replace x.x.x.x with the IP address of your MS CA server). You will be presented with the certificate services interface (see below).
  2. Select the task Request a Certificate.
    How to use Microsoft Certificate Authority
  3. Click advanced certificate request.
    How to use Microsoft Certificate Authority
  4. Select Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
    How to use Microsoft Certificate Authority
  5. Copy and paste the contents of the CSR in the Saved Request box.
  6. Select Web Server under Certificate Template.
    How to use Microsoft Certificate Authority
  7. Select DER encoded and click Download Certificate. Save the file to your local system using whatever name you wish this file will be imported into SonicWall appliance.
    How to use Microsoft Certificate Authority

    How to use Microsoft Certificate Authority
     

 Validating the Certificate on the SonicWall Appliance
  1. Navigate to System | Certificates page.
  2. Click Upload Signed certificate 
    How to use Microsoft Certificate Authority
    for the certificate that has type Pending request. 
    How to use Microsoft Certificate Authority

  3. Browse for the downloaded file from the CA and click Upload.
    How to use Microsoft Certificate Authority


    How to use Microsoft Certificate Authority
  4. Once the certificate has been uploaded, the certificate will show type as Local Certificate and Validated as YES.
    How to use Microsoft Certificate Authority


How to Test

Now that a signed certificate has been imported into the SonicWall, it can be used for HTTPS management of SonicWall interfaces as well as for SSL-VPN. To set the imported certificate as the management certificate, perform the following steps

  1. Navigate to Appliance | Base Settings.
  2. Under the Web Management Settings section, select the imported certificate under Certificate Selection.
  3. Click Accept to save the changes.
    How to use Microsoft Certificate Authority
  4. When logging into the SonicWall after importing the signed certificate you may receive the following browser errors:
    How to use Microsoft Certificate Authority

    How to use Microsoft Certificate Authority
    CAUTION: "The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority".
    You get this error because the issuing CA certificate is not in the certificate store of the browser. To resolve it, install the certificate in the certificate store of the browser.

    How to use Microsoft Certificate Authority
    CAUTION: "The name on the security certificate is invalid or does not match the name of the site".
    You get this error because you are accessing the site using a different name from the certificate Common Name (CN) you entered when creating the Certificate Signing Request (CSR). In the above example the SonicWall is being accessed using an IP address although the CN in the certificate is SonicWall.local (see above) : You have two options to overcome this error:

  • When creating the CSR enter the CN as 192.168.168.168.
  • Map the IP address of the SonicWall to the CN..
  • Where to get Netextender Cleanup Tool?
  • How to Setup the SonicWave 600 series
  • How to block Adobe Acrobat using App control?

Categories

  • Firewalls > SonicWall SuperMassive 9000 Series > System
  • Firewalls > TZ Series > System
  • Firewalls > NSa Series > System
  • Firewalls > NSv Series > System


Was This Article Helpful?

How to use Microsoft Certificate Authority
YES
How to use Microsoft Certificate Authority
NO

What is Windows certificate authority used for?

A certification authority (CA) is responsible for attesting to the identity of users, computers, and organizations. The CA authenticates an entity and vouches for that identity by issuing a digitally signed certificate. The CA can also manage, revoke, and renew certificates.

How do I run certificate authority?

Select your root certificate file. Search for whatever your CA name. Double click on your root certificate in the list..
Open a Command Console..
Enter openssl genrsa -des3 -out myCA. ... .
When prompted, enter your passphrase..

How do I create a certificate using Microsoft certificate authority?

In a browser, open the page of your Certification Authority: https:///certsrv ..
Select Request a certificate. ... .
Select advanced certificate request. ... .
Select Create and submit a request to this CA. ... .
In the Certificate Template drop-down list, select Subordinate Certification Authority..

What is certificate authority and how it works?

A certificate authority (CA) is a trusted entity that issues Secure Sockets Layer (SSL) certificates. These digital certificates are data files used to cryptographically link an entity with a public key. Web browsers use them to authenticate content sent from web servers, ensuring trust in content delivered online.