hi all
we solved ( windows only .... eh eh ) ;-)
First above all I forgot to inform you we are working on a WIN 2003 Server and OpenSSL is not intalled on this machine.
Solution , we generate the key in the keystore first , after we export the key inside a .cer file, third we use the certutil.exe tool to import the key directly inside IE.
Here our files :
************** ssl.txt *****************************
c:\sahi\bin\crea_certificato.bat $keytool $domain $password $keystore
****************************************************
************ c:\sahi\bin\crea_certificato.bat ( batch file called from ssl.txt ) **********
set keytool=%1
set domain=%2
set password=%3
set keystore=%4
cd \sahi\certs\
%keytool% -genkey -alias %domain% -keypass %password% -storepass %password% -keyalg RSA -keystore %keystore% -validity 2000 -dname "CN=%domain%, OU=Sahi, O=Sahi, L=Bangalore, S=Karnataka, C=IN"
%keytool% -export -alias %domain% -keypass %password% -storepass %password% -keystore %keystore% -file %keystore%.cer
certutil -addstore ROOT %keystore%.cer
*********************************************************************
So we can now schedule every midnight a certificates clean-up inside the c:\sahi\certs directory in order to automatically accept new site certificates ( new site checked or new certificate due expiration )
cheers
Massimo
Massimo Borgogno
Consultant assioma.net S.r.l. http://www.assioma.net
Csi Piemonte Monitoring team : http://www.csipiemonte.it