SubCA cert template problem


hello,

i've encountered problem cert template subordinate ca. in windows 2008 r2 there 'subordinate certification authority' length not satisafctory. i've duplicated template, set length validity 10 years , on 'security' tab i've added administrators , enterprise administrators privileges read/register/auto-enroll. enrollment of subca impossible now. had message

http://img573.imageshack.us/img573/9932/skrin1.jpg

which means primary ca rejected request because refers template not supported active directory certificate services: subca.

what problem? situation in topology:
ca-03 ----requests cert ------> ca02

please, help
best

sorry overlooked 1 point. when setup enterprise subca , request certificate uplevel enterprise ca (root or subca) wizrd hardcode certificate template subca. in order use custom certificate template subordinate ca must add following lines capolicy.inf:

[requestattributes]
certificatetemplate = <your custom subca template>

and run installation wizard again.

note: must specify template common name (not display name). 


http://en-us.sysadmins.lv


Windows Server  >  Security



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...