Solved

Certificate authority web enrollement problem

Posted on 2010-09-08
5
1,192 Views
Last Modified: 2013-12-08
Hello..

I am using windows 2008 server and I am trying to use web certificate enrollment option, but it dose not work.

I am trying to generate  certificates for smart card log-in for some users, while using web enrollment. I am using Safe Sign as CSP.

If i do enrollment on behalf of some user while using MMC snapin for certificates the thing is working well, users can log in with no problem using there cards and pin number. Smart card contains everything (identity ,cert .. ) that it should
.. but if i do enrollment in IE (web enrollment), all i get writen on smart card is "unknown" (identity, cert, key ..)

Strange thing is, when you look at issued certificates under AD users and computers , the certificate is there.. everitjhing seems ok.. its just not writen coorect on smart card.

Anny idea ?
0
Comment
Question by:schkratek
  • 3
  • 2
5 Comments
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
When you use Web Enrollment, do you accept them then in CA console? Users make requests but admin has to accept the to be issued. Then they come back to Web Enrollment page and downloads it.
0
 

Author Comment

by:schkratek
Comment Utility
I have no pending requests..
0
 

Author Comment

by:schkratek
Comment Utility
Request Handling is not explicit
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
Probably that template is old, so first you should duplicate it, creating new template version but...

I think that would be a problem, certificates cannot be requested via Web Enrollment because Windows Server 2008 Web Enrollment doesn't support them (certificates version 3)

http://blogs.technet.com/b/ad/archive/2008/06/30/2008-web-enrollment-and-version-3-templates.aspx
http://technet.microsoft.com/en-us/library/cc732517%28WS.10%29.aspx (look for "Certificate Web enrollment cannot be used with version 3 certificate templates")
0
 

Accepted Solution

by:
schkratek earned 0 total points
Comment Utility
template is already duplicated... and also solution is at hand..

when doing it over the web.. i always requested the certificate ( as in MMC snapin) but in mmc certificate is automatic written to the smart card, while over web, you have to press install certificate after the first write on smart card is completed.. (so it takes two writest on smartcadr over the web)



0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

OfficeMate Freezes on login or does not load after login credentials are input.
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now