Enroll on Behalf of Smartcard Logon Certificate


i've stood server 2008 r2 enterprise ca, , created duplicate "smartcard logon" template.

on client (whether it's on win7 or win8), success requested , received enrollment agent certificate in personal store.  ca certificate in trusted root , intermediate ca store, ntauth container.

everything appears going well, until tried "enroll on behalf of" user smartcard logon certificate.

when selected "enroll on behalf of," prompted browse enrollment agent certificate.  when clicked on browse, says no certificate available, though, it's in personal store.  requested , received new enrollment agent certificate, same issue.

i'm out of ideas.  appreciated.

thank you.



ok, - had encountered both issues: app. policy config , issue chain!

this chain validation error quite uncommon.

have probably disabled crl checking in gpo ca described here without setting ocsp url?

background:

according documentation error the certificate not in revocation server's database (crypt_e_not_in_revocation_database) means or can mean cryptoapi looks ocsp urls. though crls validate fine check fails don't use ocsp.

in order confirm turn on capi2 logging in event viewer (in folder ms specific logging options). here validation of every certificate chain logged - see lots of messages related other certificates.

among messages related agent certificate there should task called verify revocation. in details expect find cert_verify_rev_server_ocsp_flag="true" (only ocsp evaluated) similar dump here.

so need find windows setting (as gpo) or third-party application has set flag.

elke




Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group