locked
Autoenroll User Certificate with 2K8 R2 CA RRS feed

  • Question

  • The setup is this:

    - Offline root CA, 2K3
    - Policy/Issuing CA 1, 2K8 R2
    - Policy/Issuing CA 2, 2K8 R2
    - Windows XP SP3 client

    I duplicated the Code Signing certificate on one of the 2K8 R2 CAs and was prompted to select the Windows Server version for the duplicate template; the choices were Windows Server 2003 or Windows Server 2008. As I had a 2K8 R2 CA, I opted for Windows Server 2008. I configured the certificate template for autoenrollment, securing the template against a global group called Template 1 and granting Read, Enroll and Autoenroll permissions. Try as I might, I could not get the certificate to automatically enroll for a member of Template 1 when they logged on. After adding a registry key so that autoenrollment messages were added to the event log, all I could see was Autoenrollment starting, followed by Autoenrollment finishing!

    I repeated the process above duplicating the same template, but chose Windows Server 2003 instead of Windows Server 2008 at the prompt. Autoenrollment now works!

    All I want to ask is 'Why?'

    Is it because the root CA is 2K3, as I thought the prompt would refer only to the CA where the template existed?

    Steve G

    Wednesday, February 3, 2010 10:30 PM

Answers

  • The catch is that you have Windows XP SP3 clients.
    A v3 certificate template (2008 version) implements CNG.
    Windows XP cannot consume/enroll a certificate that implements CNG
    You have to deploy certificates that the clients can enroll.
    BTW, This is a common misconception
    Brian

    Wednesday, February 3, 2010 11:50 PM

All replies

  • The catch is that you have Windows XP SP3 clients.
    A v3 certificate template (2008 version) implements CNG.
    Windows XP cannot consume/enroll a certificate that implements CNG
    You have to deploy certificates that the clients can enroll.
    BTW, This is a common misconception
    Brian

    Wednesday, February 3, 2010 11:50 PM
  • Brian,

    Thanks for inducing a forehad-slapping moment! I had forgotton about the CNG requirements for v3 templates...it was getting late!

    Steve G
    Thursday, February 4, 2010 7:17 AM