Join a domain with smarcard


env:

windows pki offline root , online issuing ca.

dcs 2008r2, fl 2008r2.

smartcard logon works fine on domain joined machines

when user (with rights so) tries join machine domain using smart card gets error:

the event log says:

the subject of sc certificate contains domain in form dc=

the user's upn in subject alternative name of cert.

i added root , issuing certs smartcard well, still getting same error.

what missing?!?!


thank you,

you try exporting dc cert , placing on test client hasn't joined domain. run certutil -urlfetch -verify <dccert.crt>, replacing <dccert.crt> export dc cert file see client can validate. perhaps crl information in ad , since hasn't joined domain yet can't validate cas. speculative , output above command help. against smart card client cert too.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...