Windows 2003 Enterprise CA - Basic EFS Autoenrollment

Can one of you experts tell me or point me to a link that tells me why my Enterprise CA (running on 2k3 enterprise) autoenrolls BASIC EFS cert requests although that template show Not Allowed for Auto enrollment?  If this is by design, do I really need it and can I turn it off without affecting other templates I want to autoenroll?  It looks to me like the User template provides the same functionality.  I have searched the net for the last several hours and cannot find anything specific to this.

Thanks in advance.

Danny
dmccampbellAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

TheCleanerCommented:
From here: http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/certenrl.mspx

EFS always attempts to enroll for the Basic EFS template. The EFS driver generates an autoenrollment request that Autoenrollment tries to fulfill. For customers that want to ensure that a specific template is used for EFS (such as to include key archival), the new template should supercede the Basic EFS template. This will ensure that Autoenrollment will not attempt enrollment for Basic EFS any more.


Basically you have to create a new templte that supercedes the Basic template if you do not want it to attempt auto-enrollment.

Strange, but true.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
dmccampbellAuthor Commented:
Tried what you suggested and per the link you provided and dup'd the Basic EFS Template making it to supercede the original Basic EFS.  However, users are still autoenrolling Basic EFS.  What did I miss?
0
TheCleanerCommented:
Did you create a brand new template or just copy and change the Basic EFS template?  I think it's saying to create it from scratch, but I'm not sure myself.

Are you sure it's trying to auto-enroll the original Basic, or is it now trying to auto-enroll the one you dup'd?
0
dmccampbellAuthor Commented:
That must have been it.  All seems to be working well now.  Thanks.
0
TheCleanerCommented:
Cool deal...
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.