CERT_TRUST_IS_NOT_SIGNATURE_VALID when installing a 3rd-party cert in Windows 2008 Domain Controller

Hello,
I'm facing with a problem while trying to install a 3rd-party digital certificate on a Windows 2008 Domain Controller.
Basically, I'm following this TechNet
http://technet.microsoft.com/en-us/library/cc783835(v=ws.10).aspx
1) I did create the file Reqdccert.vbs on the Domain Controller
2) then I did generate the inf file
cscript reqdccert.vbs DomainController E
3) and then I generated a certificate request
certreq -new AD.inf AD.req
4) also I've imported RootCA and SubCA into the Certificate Store of the DC
5) I got a signed certificate from our 3rd-party CA running on Windows 2000
6) when importing the certificate I get the below error
C:\>certreq -ACCEPT ad.p7c
Certificate Request Processor: The signature of the certificate cannot be verifi
ed. 0x80096004 (-2146869244)
Here is the verbose log from CAPI2:
+ System 
  - Provider 
   [ Name]  Microsoft-Windows-CAPI2 
   [ Guid]  {5bbca4a8-b209-48dc-a8c7-b23d3e5216fb} 
   EventID 11 
   Version 0 
   Level 2 
   Task 11 
   Opcode 2 
   Keywords 0x4000000000000003 
  - TimeCreated 
   [ SystemTime]  2014-06-13T09:33:02.604870500Z 
   EventRecordID 304 
   Correlation 
  - Execution 
   [ ProcessID]  1700 
   [ ThreadID]  3032 
   Channel Microsoft-Windows-CAPI2/Operational 
   Computer ad.eac.igs 
  - Security 
   [ UserID]  S-1-5-21-4171312682-976198474-2692596432-500 
- UserData 
  - CertGetCertificateChain 
  - Certificate 
   [ fileRef]  4DA02894B4AFB76F8D6B8722A96A3444041573C6.cer 
   [ subjectName]  ad.eac.com 
  - AdditionalStore 
  - Certificate 
   [ fileRef]  691847ADD248AEB8579462249B063A1555716B21.cer 
   [ subjectName]  SubCA 
  - Certificate 
   [ fileRef]  4DA02894B4AFB76F8D6B8722A96A3444041573C6.cer 
   [ subjectName]  ad.eac.com
  - Certificate 
   [ fileRef]  0175DDA12776ED8CA4657E921E9AE3C6B0698F71.cer 
   [ subjectName]  RootCA 
   ExtendedKeyUsage 
  - Flags 
   [ value]  0 
  - ChainEngineInfo 
   [ context]  user 
  - AdditionalInfo 
  - NetworkConnectivityStatus 
   [ value]  1 
   [ _SENSAPI_NETWORK_ALIVE_LAN]  true 
  - CertificateChain 
   [ chainRef]  {0B005F9F-F15B-4FE2-A630-7BBEE6AB5C0A} 
  - TrustStatus 
  - ErrorStatus 
   [ value]  8 
   [ CERT_TRUST_IS_NOT_SIGNATURE_VALID]  true 
  - InfoStatus 
   [ value]  0 
  - ChainElement 
  - Certificate 
   [ fileRef]  4DA02894B4AFB76F8D6B8722A96A3444041573C6.cer 
   [ subjectName]  ad.eac.com 
  - SignatureAlgorithm 
   [ oid]  1.2.840.113549.1.1.11 
   [ hashName]  SHA256 
   [ publicKeyName]  RSA 
  - PublicKeyAlgorithm 
   [ oid]  1.2.840.113549.1.1.1 
   [ publicKeyName]  RSA 
   [ publicKeyLength]  2048 
  - TrustStatus 
  - ErrorStatus 
   [ value]  8 
   [ CERT_TRUST_IS_NOT_SIGNATURE_VALID]  true 
  - InfoStatus 
   [ value]  4 
   [ CERT_TRUST_HAS_NAME_MATCH_ISSUER]  true 
  - ApplicationUsage 
  - Usage 
   [ oid]  1.3.6.1.5.5.7.3.1 
   [ name]  Server Authentication 
  - Usage 
   [ oid]  1.3.6.1.5.5.7.3.2 
   [ name]  Client Authentication 
  - Usage 
   [ oid]  1.3.6.1.4.1.311.20.2.2 
   [ name]  Smart Card Logon 
   IssuanceUsage 
  - ChainElement 
  - Certificate 
   [ fileRef]  691847ADD248AEB8579462249B063A1555716B21.cer 
   [ subjectName]  SubCA 
  - SignatureAlgorithm 
   [ oid]  1.2.840.113549.1.1.5 
   [ hashName]  SHA1 
   [ publicKeyName]  RSA 
  - PublicKeyAlgorithm 
   [ oid]  1.2.840.113549.1.1.1 
   [ publicKeyName]  RSA 
   [ publicKeyLength]  2048 
  - TrustStatus 
  - ErrorStatus 
   [ value]  0 
  - InfoStatus 
   [ value]  101 
   [ CERT_TRUST_HAS_EXACT_MATCH_ISSUER]  true 
   [ CERT_TRUST_HAS_PREFERRED_ISSUER]  true 
  - ApplicationUsage 
   [ any]  true 
   IssuanceUsage 
  - ChainElement 
  - Certificate 
   [ fileRef]  0175DDA12776ED8CA4657E921E9AE3C6B0698F71.cer 
   [ subjectName]  RootCA 
  - SignatureAlgorithm 
   [ oid]  1.2.840.113549.1.1.5 
   [ hashName]  SHA1 
   [ publicKeyName]  RSA 
  - PublicKeyAlgorithm 
   [ oid]  1.2.840.113549.1.1.1 
   [ publicKeyName]  RSA 
   [ publicKeyLength]  2048 
  - TrustStatus 
  - ErrorStatus 
   [ value]  0 
  - InfoStatus 
   [ value]  10C 
   [ CERT_TRUST_HAS_NAME_MATCH_ISSUER]  true 
   [ CERT_TRUST_IS_SELF_SIGNED]  true 
   [ CERT_TRUST_HAS_PREFERRED_ISSUER]  true 
  - ApplicationUsage 
   [ any]  true 
  - IssuanceUsage 
   [ any]  true 
  - EventAuxInfo 
   [ ProcessName]  certreq.exe 
   [ startTime]  2014-06-13T09:32:53.369Z 
   [ endTime]  2014-06-13T09:33:02.604Z 
   [ duration]  PT9.232850S 
  - CorrelationAuxInfo 
   [ TaskId]  {A8DC7725-FEE9-4E09-905A-FEFF7FAE9B8B} 
   [ SeqNumber]  27 
  - Result The signature of the certificate cannot be verified. 
   [ value]  80096004 
Any idea what the problem is?
Thanks in advance,
Davide.

One common reason for that error is that the wrong SubCA certificate had been imported accidentally - e.g. an earlier 'version' of that SubCA with the same Subject CA name but a different key. In this case the validating client will try to build a chain
based on name only but finally the signature check fails.
Could you cross-check if the extension Authority Key Identifier in your DC certificate is the same as the field
Subject Key Identifier of the SubCA certificate? (These are typically hashes of the keys though it is not standardized - it should be a unique string characteristic for the CA)
For the client cert. CERT_TRUST_HAS_NAME_MATCH_ISSUER is indicated in your log - thus Isser name in client cert. matches Subject Name in CA cert, but we don't know about SKI/AKI.
Elke

Similar Messages

  • Issue with Installing Oracle 10g R2 on a Windows 2008 Domain Controller

    I'm assigned a evaluation task for my company. The task invoke to install oracle in my Domain Controller Server.
    I got "ORA-12560: TNS:protocol adapter error" when I installed ORACLE 10g R2 for Win2K8 on my Windows 2008 (a Domain Controller Server). It happened in the create predefined database period.
    I tried to google and noted that there are some RUMOS say "We cannot deploy ORACLE on a Domain Controller, It's impossible"
    Is this true? Please, Please advise!
    Thansk,

    This is a link to a same issue
    Creating instance oracle 10.2.0.4 on Windows 2008 32bit

  • Uploading 3rd Party Cert NOT Working Prime LMS 4.2

    Hi all,
    I followed the next steps but when I tried to upload the 3rd party cert into the Prime LMS using SSL Utlity Script option 5 or 6, the process is stuck. I did not get a message similar to step 4 like: "introduce the location of the certificate...."
    1.-Create a CSR using OpenSSL as usual. (it always works on Cisco ISE, ACS, etc).
    2.-Create the LMS Server Certificate on my local CA Server using the previous CSR.
    3.-Downloaded the CA Root & Intermediate Servers Certificate (Base64 Encoded - In fact the Cisco Guide DO NOT MENTION this part, only when I ran the OPTION 4, I realized I needed it instead of DER Encoded I have been using regularly).
    4.-Downloaded the Prime LMS New Certificate, again 64Base Encoded.
    5.-Using SSL Utility Script, I ran Option 4 to validate the Certificates previously downloaded and the process went sucessful. No error messages.
    6.-TRY TO UPLOAD the LMS and CA Server Certificates but the process is STUCK after introducing YES whe this is required.
    Any ideas about this (may be is a bug or similar)?
    thanks
    Abraham

    I get the identical message with a USB audio device (Cakewalk UA1G) attached to the camera connection kit. I started getting the message after I upgraded to 4.2.1.
    I started a thread about it here this morning...
    Apple has done something unpleasant to the USB power requirements in the 4.2.1 upgrade.

  • Installing CF8.0.1 64 on Windows 2008 Serv

    Does anyone have a set of instructions on installing CF8.0.1
    64bit on Windows 2008 Server. I have tried on and off for the last
    two weeks and have made no progress. The install goes great,
    however the CF administrator component of the install fails with a
    HTTP Error 500.0 - Internal Server Error. IIS7 worked fine prior to
    coldfusion installation, however once CF 8.0.1 gets installed IIS7
    appears to break. I've read the other thread in the forum and the
    suggestions made there don't help or have already been done.
    Module IsapiModule
    Notification ExecuteRequestHandler
    Handler AboMapperCustom-72626
    Error Code 0x800700c1
    Most likely causes:
    - IIS received the request; however, an internal error
    occurred during the processing of the request. The root cause of
    this error depends on which module handles the request and what was
    happening in the worker process when this error occurred.
    - IIS was not able to access the web.config file for the Web
    site or application. This can occur if the NTFS permissions are set
    incorrectly.
    -IIS was not able to process configuration for the Web site
    or application.
    -The authenticated user does not have permission to use this
    DLL.
    -The request is mapped to a managed handler but the .NET
    Extensibility Feature is not installed.
    Things to try (from the error summary page)
    - Ensure that the NTFS permissions for the web.config file
    are correct and allow access to the Web server's machine account.
    - Check the event logs to see if any additional information
    was logged.
    - Verify the permissions for the DLL.
    - Install the .NET Extensibility feature if the request is
    mapped to a managed handler.
    - Create a tracing rule to track failed requests for this
    HTTP status code.
    Adobe in going to expect a $6700 check from me in another
    week or so and the damn thing doesn't install to the point where
    the demo's will run. Windows 2008 and IIS7 isn't that new and I
    can't imagine that the number of people having done this is limited
    to the one or two in this forum and that there is no technote avail
    to us that have to depend on internet support and published
    technotes that can document the installation procedure of CF 8.0.1
    64bit on windows 2008.
    It's the fourth of July and this is a fine place to be.
    Happy 4th everyone!

    Please see this link:
    http://www.jasonholden.com/blog/index.cfm/2008/5/6/Coldfusion-8-on-Windows-Server-2008

  • I am having a problem installing the x86 drivers on a Windows 2008 server for a hp 4000n.

    I am having a problem installing the x86 drivers on a Windows 2008 server for a hp laserjet 4000n.

    Hi all,
    Sylonious, did you manage to sort this problem out? I have been experiencing similar problems. I think my problem was because I had many different versions of JDKs. I have done a complete re-install. I would be really grateful to you (and anyone else) for help with this problem.
    I have re-installed JSDK1.4.2_03, set the "path" variable to "C:\JSDK1.4.2_03".
    When I compile using "javac" I get an error saying "javac" is not recognised.
    When I compile using "C:\j2sdk1.4.2_03\bin\javac Freq.java" no error is thrown.
    Every time I try to run a java file, I always get the NoClassDefFound error. When run with the -verbose option, files are loaded from C:\Program Files\Java\j2re1.4.2_03\bin - is this correct?
    I have removed all previous references to java in the registry editor.
    Please help !
    Regards,
    Vipul

  • How to install a plugin on 64 bits windows 2008 server?

    From the developer forum, I found a description which told me how to install a plugin on windows series system, but I only succeded intalling the plugin on 32 bits windows xp, couldn't install the plugin on 64 bits windows 2008 server. Any ideas or advices, men of genius? Thanks :-)

    Please check if all your plugins are up-to-date. To do this, go to the [http://mozilla.com/plugincheck Mozilla Plugin Check site].
    Once you're there, the site will check if all your plugins have the latest versions.
    If you see plugins in the list that have a yellow ''Update'' button or a red ''Update now'' button, please update these immediately.
    To do so, please click each red or yellow button. Then you should see a site that allows you to download the latest version. Double-click the downloaded file to start the installation and follow the steps mentioned in the installation procedure.

  • Can install Oracle 10g release 2 on Windows 2008 R2 Server  64-bit machine

    Hi All,
    Can we install Oracle 10g Release 2 on Windows 2008 Server R2 for 64-bit machine? If yes then is there any patche requirement for this, So suggest me.
    Regards,
    Rizi

    Hi;
    Can we install Oracle 10g Release 2 on Windows 2008 Server R2 for 64-bit machine? If yes then is there any patche requirement for this, So suggest me.Yes you can but you must use 10.2.0.5.0 version. Pelase check below note:
    How to Install Oracle 10.2.0.5 on MS Windows 7 / Windows 2008R2 [ID 1173433.1]
    Regard
    Helios

  • Error Installing AD Password sync connector in windows 2008

    HI,
    i am trying to install AD Password sync connector in windows 2008 but i am getting following error.
    **Error occurred while uploading prepAD.ldif. , please refer to %TEMP%\oimpwdsync.log. Please upload**
    **prepAD.ldif to Active Directory Domain Controller before applying ACLs.**
    Thanks,

    Dont do any thing. just restart your machine,a dn re-configure, because first time passwordsync10.dll has not initialized on AD machine. after that just put same parameter value what you have given previously. it will work
    same time verify if AD Authentication or xelsysadm Authentication is wrong

  • Install ODI 10g on  64 bit Windows 2008 server

    Can we install ODI 10g on 64 bit Windows 2008 server ? if so Please provide the me the link for download
    Edited by: user1137989 on Oct 27, 2010 10:51 PM

    If you are looking for 10g then scroll down in the link (http://www.oracle.com/technetwork/middleware/data-integrator/downloads/index.html) Oracle Data Integrator 10g (10.1.3.5.0) and select for Microsoft Windows (x86) and extract and install .
    11g comes in 32 and 64 bit version .
    32 bit version is
    Oracle Data Integrator 11g (11.1.1.3.0)
    for Microsoft Windows (x86)
    64 bit version is .
    Oracle Data Integrator Companion 11g (11.1.1.3.0)
    for All Platforms
    Hope this helps .

  • Archive & Install leaves 3rd Party Apps (some with probs)

    I've been on the phone with AppleCare two times about this. Here's the bottom line:
    I installed Leopard (just the default upgrade) and the 10.5.1 upgrade. All was ok for a while. All programs (including 3rd party) were working. Then I took the laptop in to the Genius bar because I thought I had a battery problem and the system seemed sluggish. They ran Disk Utility from their store server which was NOT running Leopard and repaired permissions on my laptop from there. Then they ran Disk Utility from my computer (Leopard 10.5.1) and sent me on my way since the disk verified ok. Then the problems started:
    1. Desktop Wallpaper was discarded and replaced by default
    2. Printers disappeared and could not produce PDFs via an Adobe PDF printer
    3. A 3rd party wordprocessor (Mellel) would not open existing documents and would not open a new document (no blank page, no error, nothing)
    AppleCare instructed me to re-install Leopard with "Archive & Install" but warned that I would have to reinstall (most) third party programs. Trouble is, all my programs remained. The Adobe PDF printer problem was resolved, but the Mellel problem persisted. I called AppleCare again and they were perplexed as to how an Archive & Install could still have all the apps in the regular Application folder (and of course the icons in the dock too). The "Previous Systems" folder from the Archive seemed incomplete to them, so they suggested that the install was compromised somehow and to do another "Archive & Install." The goal would be to have another "Previous System" folder from the archive, and a clean Application folder with no third party software in it.
    Well, 3 hours later, I have a re-installed Leopard and I still have all my applications (and of course, Mellel still does not work).
    So, any suggestions out there? Are my installation disks messed up or should I go ahead and wipe the disk and start completely from scratch? I've got my library archived and my documents backed up. Anything else I should do if the recommendation is that I wipe it clean?
    Karyn

    OK, here is the "resolution" of the issue.
    1. The issue was finally decided to be the fact that the Genius Bar used a non-Leopard system to do the Permissions Repair on a Leopard system. Apparently, 10.4 and 10.5 handle the repairs differently. Leopard actually also takes much longer. Apple Support (phone) said that 10.4 checks things differently and can alter/repair items that can make them unable to be understood by 10.5. This was the original issue which then led to me not being able to use my third party applications and to losing network settings and printer settings. Then because Apple Support kept having me do an Archive and Install preserving User settings the corrupted information kept perpetuating itself. The solution (unfortunately) was to do an Erase and Install and lose all the user settings. I called the Genius Bar at the retail location where I went last Monday to make sure they were aware of this issue so that other people do not waste as much time as I did this week on computer issues. I am mostly upset because this was a very preventable issue and I didn't need to lose so much work time right before the holidays. The Genius folks should have known better!
    2. An option when doing Erase and Install is to migrate a backup from Time Machine. Since I had nothing to lose the Apple Support folks suggested that I use that option, so I tried that. I used a Time Machine backup which was prior to the issue with the Genius Bar. Unbelievably, it seems to have worked. At least I am back to just the issues (sluggishness) that I had when I started going to the Genius Bar.
    Thanks for all your ideas and help in narrowing down the issue.

  • Clean Install On 3rd Party SSD

    My brother has given me his 2010 MacBook Pro with a 256GB SSD running 10.9 and I want to do a clean install of OS X 10.10. Can this be done with a Bootable USB? I have read a few things about this called Trim and was wondering if I need to do something else? It is an aftermarket SSD (256GB OCZ Agility 3 SSD Drive) can I do a clean install straight away or do I need to do something else? Sorry for the newbie question and sorry if this has been asked, but I could not find an answer anywhere.

    To create a bootable USB, you use Diskmaker X
    <http://liondiskmaker.com>
    TRIM is a nice addition, but not essential.  In Yosemite, the only way to enable TRIM for a 3rd party SSD, is to disable some Mac OS X security features.
    <https://www.cindori.org/trim-enabler-and-yosemite/>
    TRIM is a way for the file system to tell the SSD that a set of storage blocks were just deleted from a file, and the SSD is allowed to pre-erase them so they are ready to be re-used by the SSD.  And SSD cannot overwrite a block with data in it.  The SSD must perform a special kind of erase that when issued erases a much larger region of storage.  So the SSD, used a block remapping algorithm that takes a pre-erased block and write to that, then remaps that block so it looks like the block the file system asked to be written.  The file system thinks it has overwritten the block it specified, but in reality it wrote to a totally different physical block, and the SSD just makes it look like it.
    To be able to do this the SSD needs a pool of pre-erased blocks, or it much find a region to erase, save any blocks in that region that have active data on them, then if necessary re-write blocks it could not find new home for, and write the data the file system wanted written.  This read, erase, write is more time consuming, so it pays for the SSD to have a pool of pre-erased blocks.  SSDs generally "Over Provisioned" so that they always have spares that file system does not know about.  Those over provisioned spares are also used to replace blocks and regions that have exceeded their write life (SSDs have a limited number of writes and then blocks and regions start to fail).
    The SSD when idle will try to consolidate regions so it can have a pool of pre-erased blocks.  TRIM support just gives the SSD a larger pool so that if you are doing a huge write (copying some multi-gigabyte sized files disk to disk), the SSD will not easily drain its pool of pre-erased blocks.
    But Mac OS X will still run faster with an SSD, even without TRIM, than it would on a rotating hard disk.  It will always read faster, and as long as you are not doing non-stop writes, the SSD will catch up and maintain a pool of pre-erased blocks for the next moderate write.
    Some SSD vendors give more of the SSD to over provisioning, such as OWC where their SSD sizes are 240, 480, 960, instead of 256, 512, 1024, with the difference going to create a larger over provisioning pool so the SSD has more storage the file system does not know about to try and keep ahead of large write operations.

  • I have a brand new iMac that does not have iDVD. Made a move on iMovie installed a 3rd party burn prog. but DVD won't playback on my regular dvd player. Need to burn one that will. Help!

    My new iMac did not come with iDVD as they are not using iDVD any longer.  I made a movie that I needed to put on a DVD that would play on any external DVD player. After calling Apple twice, they recommened a 3rd party program so I downloaded "Burn-osx" and made the DVD; however when i insert it into my player connected to the TV it gives the message "disk error --playback feature may not be available on this disk".  Ok--now what?  I am up against a time line here--need the DVD for a graduation party! Help! What am I not doing correctly?

    I have a brand new iMac
    If you are still within your 15 day return period.  Call Apple they will sent out iDVD at no charge.  (There are no realistic substitutes.)
    Nicely explain that you may return the computer without iDVD. That usually does the trick.  You MUST speak to a senior advisor to get a free copy. The first tier people cannot do it.
    408-996-1010
    800-692-7753
    If that doesn't work you can purchase iLife 11  (includes iDVD) on disk.
    IDVD is a wonderful piece of software and well worth the low cost of $40.
    http://www.amazon.com/Apple-MC623Z-A-iLife-VERSION/dp/B003XKRZES/ref=sr_1_1?ie=U
    they recommened a 3rd party program so I downloaded "Burn-osx"
    Yes, there are programs that will put a movie on a DVD.   I have tried most of the other substitutes including Toast, Burn, and others.  None of them come anywhere near the ease-of-use and power of iDVD. IDVD is specifically designed to work with iMovie. Get iDVD.

  • Duplicate transactions in GL Journals when imported from 3rd party

    Hi All,
    Normally everyday we receive data from 3rd party system will imported to GL via GL interface tables. A scheduled program 'Journal import' is being scheduled every night which was in error status since last 4 days.
    So we have deleted certain transactions from the GL interface tables using delete command and imported the good ones into GL. Now when we see the amount is doubled.
    Any ideas. Have we done anything wrong?
    This is 11i.
    Thankyou in advance,
    Sudah

    Hi All,
    The journals that were imported are in Posted status. We have more journals than expected like almost doubled. what is the fix for this.
    Please help.
    Regards,
    Sudha

  • Unable to install any 3rd party applications

    I have a nokia e61. I have been trying to install 3rd party apps like newsgator, truphone, google maps etc on my phone. It dowloads the applications and immediately thereafter gives me a message 'Unable to install'. Any suggestions anyone.

    Hi,
    Yes, i've tried that step with a 6630, N95 and E61 !
    Works like a charm!
    Cheers
    Let me be a ripple in the silent stream of your memory ~ Viveca

  • Which process chain type used when scheduling from 3rd party

    Do we use Local Process Chain or Meta Chain type used when triggering  PC from 3rd Party scheduling tools like Redwood..
    Any inputs...
    Venkat.

    Hi Venkat,
    Select "Start Using Meta Chain or API" for the start process when running a process chain from a third party scheduling software or when calling a process chain from within another process chain. 
    I also believe some third party scheduling software will also work if you set the start process to  "Direct Scheduling" and set the start time to immediate but I would recommend just making it a Meta Chain for tracking purposes.
    Thanks,
    Damon Fahey

Maybe you are looking for

  • SSRS expression for division

    Hi All, Below is the my table with SSRS expressions marked as A and B  Expression A gets the serial number 1, 2, 3 etc I need to get expression A/B Any help on this much appreciated Thanks  Pradnya07

  • Activation at store/home

    I reserved my iphone to pick up at the apple store. Do I have to let them activate it or can I do it in the comfort of my home. Also, let's say they have problems activation(as some others have said happened with 3gs), can I just continue to use my o

  • Complex  vs Simple in java?

    {color:#000000}Over time i have noticed that Simple {color}{color:#000000} coding {color}{color:#000000}does have larger files and easy to Understand code but on the other hand Complex coding does a great lot of work done with less lines of code and

  • Missing tab in the systems properties box in windows 8.1

    I have done sometime along the way that has caused me to lose the system protection tab in the system properties box.  I have done a virus scan using norton 360 and have found nothing.  Please help me to restore this tab so that I can manually create

  • What's with TV downloads available if purchased individually but not with Season Pass?

    I purchased a season of Smash. The only notification I have received of available downloads are the first two episoides (pilot-1 and eposide 2).  but have not received all available downloads. There are currently 4 more eposides available but iTunes