Ascentium
asked on
Smartcard Enrollment
I need to use an enrollment station to enroll smartcards for some users. After going through the steps below I do not have this option when I navigate to the certificate enrollment page.
"Request a certificate for a smart card on behalf of another user using the Smart Card Enrollment"
Here are the steps already taken.
To prepare a smart card certificate enrollment station
On the computer that you will use to set up smart cards, install a smart card reader, following the manufacturer's instructions.
Log on as the user or administrator who will be installing certificates on smart cards.
On the taskbar, click the Start button, click Run, type mmc, and then click OK.
On the File menu, click Add/Remove Snap-in, and then click Add.
In Snap-in, double-click Certificates. If you are logged on as a user, the Certificates snap-in automatically loads.
If you are logged on as an Administrator, click My user account, and then click Finish.
Click Close and then click OK.
Double-click Certificates - Current User.
In the console tree, click Personal.
Where?
Certificates - Current User/Personal
On the Action menu, point to All Tasks, and then click Request New Certificate.
In the Certificate Request Wizard, click the Enrollment Agent certificate template and type a friendly name and a description for the certificate.
When prompted by the Certificate Request Wizard, click Install Certificate.
"Request a certificate for a smart card on behalf of another user using the Smart Card Enrollment"
Here are the steps already taken.
To prepare a smart card certificate enrollment station
On the computer that you will use to set up smart cards, install a smart card reader, following the manufacturer's instructions.
Log on as the user or administrator who will be installing certificates on smart cards.
On the taskbar, click the Start button, click Run, type mmc, and then click OK.
On the File menu, click Add/Remove Snap-in, and then click Add.
In Snap-in, double-click Certificates. If you are logged on as a user, the Certificates snap-in automatically loads.
If you are logged on as an Administrator, click My user account, and then click Finish.
Click Close and then click OK.
Double-click Certificates - Current User.
In the console tree, click Personal.
Where?
Certificates - Current User/Personal
On the Action menu, point to All Tasks, and then click Request New Certificate.
In the Certificate Request Wizard, click the Enrollment Agent certificate template and type a friendly name and a description for the certificate.
When prompted by the Certificate Request Wizard, click Install Certificate.
ASKER
Yes...already have the enrollment agent cert installed. I've already gone through all the steps in that guide. Still no option to enroll on behalf of another user.
SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
I get a page cannot be found when try to navigate to that inserting my CA Hostname.
ASKER CERTIFIED SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
Opened a PSS ticket for this. We had to uninstall a hotfix for active x controls (sorry for being vague) that essentially made it so the option to request a cert on behalf of another user did not show up. Then I had to roll back my IE version to 6 because IE 7 will not allow the active x controls for the enrollment page to run. You also have to turn off the popup blocker so you get the warning and can accept to run the active x controls. I think it may have been easier if I just uprgraded my cert server to 2008 so I could use the MMC instead.
http://support.microsoft.com/kb/257480
Do you have an enrollment agent cert yet for the admin account you're logged in as?