PRB: Exporting Multiple Certificates to .p7b Imports Bad Certificates on Second Computers (326087)
The information in this article applies to:
- Microsoft Internet Information Services 5.0
- Microsoft Internet Information Services version 5.1
This article was previously published under Q326087 SYMPTOMS
After you import and install certificates on Internet Information Services (IIS), the Secure Sockets Layer (SSL) connections may not function properly. If you are using Microsoft Internet Explorer and SSL to visit the site, you may receive the following error message:
Page cannot be displayed
You receive the following error message in Event Viewer:
Event ID: 36189
Source: SCHANNEL
Description:
The SSL server credential's certificate does not have a private key information property attached to it. This most often occurs when a certificate is backed up incorrectly and then later restored. This message can also indicate a certificate enrollment failure.
CAUSE
During the export, each certificate is exported without the private key, so the SSL connections that use these certificates are unsuccessful if they are imported on the same server or on a different server for IIS.
When certificates are exported on one computer without the private key, the certificate is rendered unusable. Therefore, exporting in .p7b format is not a valid solution for exporting certificates.
RESOLUTION
To avoid the error message, Microsoft recommends that you export certificates on a one-by-one basis when you save the exported certificates.
For additional information about exporting certificates, click the article numbers below
to view the articles in the Microsoft Knowledge Base:
232136 HOW TO: Back Up a Server Certificate in Internet Information Services 5.0
232137 How to Import a Server Certificate for Use in Internet Information Services 5.0
STATUSMicrosoft is researching this problem and will post more information in this article when the information becomes available.REFERENCESFor additional information about certificate management in IIS, click the article number below
to view the article in the Microsoft Knowledge Base:
320878 HOW TO: Manage Certificates in Windows 2000
Modification Type: | Major | Last Reviewed: | 6/29/2004 |
---|
Keywords: | kbprb KB326087 |
---|
|