1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Resolved Expired Certificate - Windows Small Business Server 2003

Discussion in 'Windows Server System' started by WFC_Exile, 2010/11/17.

  1. 2010/11/17
    WFC_Exile

    WFC_Exile Inactive Thread Starter

    Joined:
    2002/01/12
    Messages:
    97
    Likes Received:
    0
    Running Windows Small Business Server 2003 SP2 - fully updated.

    I recently began receiving this critical error in the system log in conjunction with the "Certificate Services" service stopping - and not wanting to stay started even after attempting to restart it.

    "A certificate in the chain for CA certificate 0 for [companyname1].[companyname].local has expired. A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. "

    Can anyone advise on a resolution? My searches so far have yielded no solution.
     
  2. 2010/11/18
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Have a look in the Event Log & copy the (related) error here. Have a look under Application log.

    Make sure that the CA root certificate is valid, you may need to update it.
     
    Arie,
    #2

  3. to hide this advert.

  4. 2010/11/19
    WFC_Exile

    WFC_Exile Inactive Thread Starter

    Joined:
    2002/01/12
    Messages:
    97
    Likes Received:
    0
    Information as requested.
    Server name disguised.

    Application log error message #1
    Certificate Services did not start: Could not load or verify the current CA certificate. mycompanyname1.mycompanyname.local A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495).

    Application log error message #2
    A certificate in the chain for CA certificate 0 for mycompanyname1.mycompanyname.local has expired. A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495).

    Additionally - "Certificate Services" will not remain started when restarted. So when opening Certificate Authority control - there is a red dot next to mycompanyname1.mycompanyname.local and no information is accessible because Certificate Services is stopped.

    There is an option to Renew CA Certificate - and when opened it states:
    Do you want to create a new public and private key pair? The cryptographic service and hash algorithm settings will be preserved. If the existing key length is less than 1024 bits, it may be increased. yes /no?

    I have not moved past this yes/no dialogue for fear of blowing something up - my company runs on this its only server and so far - it is still working - albeit with these new error messages every day.

    Appreciate any guidance you can supply.
     
  5. 2010/11/19
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    This is how a copied error should look like:

    That will give more info.
     
    Arie,
    #4
  6. 2010/11/19
    WFC_Exile

    WFC_Exile Inactive Thread Starter

    Joined:
    2002/01/12
    Messages:
    97
    Likes Received:
    0
    Event Type: Error
    Event Source: CertSvc
    Event Category: None
    Event ID: 100
    Date: 11/17/2010
    Time: 2:19:51 PM
    User: N/A
    Computer: MYCOMPANY1
    Description:
    Certificate Services did not start: Could not load or verify the current CA certificate. mycompany1.mycompany.local A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495).

    Event Type: Error
    Event Source: CertSvc
    Event Category: None
    Event ID: 58
    Date: 11/17/2010
    Time: 2:19:51 PM
    User: N/A
    Computer: MYCOMPANY1
    Description:
    A certificate in the chain for CA certificate 0 for mycompany1.mycompany.local has expired. A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. 0x800b0101 (-2146762495).


    Additional Information:
    "Certificate Services" will not remain started when restarted. So when opening Certificate Authority control - there is a red dot next to mycompanyname1.mycompanyname.local and no information is accessible because Certificate Services is stopped.

    There is an option to Renew CA Certificate - and when opened it states:
    Do you want to create a new public and private key pair? The cryptographic service and hash algorithm settings will be preserved. If the existing key length is less than 1024 bits, it may be increased. yes /no?

    I have not moved past this yes/no dialogue for fear of blowing something up - my company runs on this its only server and so far - it is still working - albeit with these new error messages every day.

    Appreciate any guidance you can supply.
     
  7. 2010/11/20
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    I'm sorry, but I can't help any further. I've never worked with certificates, and the only suggestion I have is to check your clock or update the root certificate.
     
    Arie,
    #6
  8. 2010/12/02
    WFC_Exile

    WFC_Exile Inactive Thread Starter

    Joined:
    2002/01/12
    Messages:
    97
    Likes Received:
    0
    For reasons that are a mystery to me and occurred with no action taken by me - the server seems to have - on its own - without a reboot - after two weeks - created a new CA certificate - called CA Certificate 1 - valid for another 5 years - Certificate Services restarted - and all error messages stopped. Go figure! Problem resolved
     
  9. 2010/12/03
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,680
    Likes Received:
    104
    :eek:

    Great.

    Please mark your thread as 'Resolved'.

     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.