Enroll on behalf of no certificates available


trying smart card authentication setup.

using dedicated ad account called eagent, verified security read , enroll certificate templates.

  1. installed ca on windows 2008 r2 - domain controller
  2. issued certificate template: enrollment agent
  3. managed templates, duplicate smartcard logon, picked server 2003 enterprise, general tab: validity 5 years, , changed display name; request handling: signature , smartcard logon; issuance requirements: 1 authorized signature, application policy type required in signature, application policy-certificate request agent.
  4. issued certificate template: smartcard logon
  5. from enrollment station (eagent logged on): installed enrollment agent personal>certificates store. status: succeeded
  6. from enrollment station (eagent logged on): personal>certificates, tasks, advanced operations, enroll on behalf of..., click next twice, when browse select enrollment agent certificate get:

no certificate available

no certificatates meet application...

click ok continue

i have been thru settings day, stumped.


michael maxwell

thank you, problem ended being local certificate store on enrollment station older certificate. once cleared out, started working.

michael


michael maxwell



Windows Server  >  Security



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...