0

I am trying to follow instructions on Technet about deploying a Standard (non-enterprise) SSTP based VPN) that were originally written for Server 2008, but I am using Server 2008 R2, I have gotten as far as the part where it asks you to create a request a Server Authentication certificate. I have deployed IIS, and Active Directory Certificate Services, and chose "Standalone" and "Standard" (non-enterprise) Certificate Authority because I don't have an OID and don't think I should have to get one for a simple deployment of SSTP.

The resulting certificates made by the Certification Authority "Issue" command, only have a 1 year period of validity, I want a multi-year certificate.

At no point in this process is there any way to input this information unless it's through the Attributes text input area on the Advance Certificate Request page, which appears to be generated using an old ActiveX control, which means I can only do this using the workarounds in the article that I linked at the top, and only using Internet Explorer.

enter image description here

Update:: I got stuck also at "The revocation function was unable to check revocation", and the VPN connection fails. This is covered by the KB article linked here.

Warren P
  • 1,195
  • 7
  • 20
  • 35
  • related information that doesn't help me (WinSrv2000,2003): http://support.microsoft.com/kb/254632/en-us – Warren P Nov 01 '13 at 16:45
  • IDEA: possible technique might be to generate an .INF file using the CAPolicy.inf syntax (in notepad). http://blogs.technet.com/b/askds/archive/2009/10/15/windows-server-2008-r2-capolicy-inf-syntax.aspx – Warren P Nov 01 '13 at 16:49
  • Can you duplicate the certificate template and increase the validity period? It's in the Certificate Template plug-in for mmc. – 0xFE Nov 02 '13 at 04:10
  • GOod idea, I'll try that. – Warren P Nov 02 '13 at 13:22

1 Answers1

1

Open the Certificate Template MMC console (certtmpl.msc). Right click the certificate template you want to modify, and click Duplicate Template. On the General tab, change the Validity Period to the desired time. You probably want to change the name as well.

Now, you want to request a certificate from the new template. You may need to add the certificate template in Certification Authority MMC console to get the new template to appear online.

0xFE
  • 201
  • 2
  • 11