Answered by:
NPS server - certificate auto-enrol

Question
-
Hi,
I'm having problems getting certificate autoenrol on internal PKI to work for wireless set up with 802.1X Authenticated Wireless Access with PEAP-MS-CHAP v2
Certificates can be generated manually and everything works perfectly, but haven't been able to get autoenrol of computer certificates working. Any advise on how to fix or troubleshoot this would be appreciated.
- GPO for autoenrol is set up as required (in the registry, AEPolicy = 7 which shows this is set correctly as per the link at bottom of this. rsop.msc also shows the policy is being correctly applied.- Enabled logging in HKLM\Software\Microsoft\Cryptography\Autoenrollment\AEEventLogLevel and can see events 64 and 65 showing when running certutil -pulse
Those events are "Certificate enrollment for Local system is successfully authenticated by policy server"
- I Followed instructions on setting up the CA side. Slight complication is that CA is in parent domain, but added NPS servers needed to autoenrol into a group (and also explicity) with required permission (read, enrol, autoenrol)
- Certificate server shows no received requests and no failed requests
Used this to set up the CA which is in production for other certificate uses. https://technet.microsoft.com/en-gb/library/cc731522.aspx?f=255&MSPPError=-2147217396
Also this one http://www.rickygao.com/how-to-automatically-enroll-user-and-computer-certificate-in-ad/Troubleshooting guide - I found this useful http://social.technet.microsoft.com/wiki/contents/articles/3048.troubleshooting-certificate-autoenrollment-in-active-directory-certificate-services-ad-cs.aspx
Environment:
NPS = Server 2012 R2 Standard
CA server = 2008 (R2 Enterprise I think)Hope someone can assist as I am stuck. Issue doesn't appear to be GPO related or CA related. Despite event ids listed above, I'm not convinced the NPS servers are even asking out for a certificate.
Wednesday, March 23, 2016 1:55 PM
Answers
-
Thanks for the response.
The issue resolved itself after a few days - for reasons unknown it suddenly auto-enrolled the certificate as originally expected.
- Proposed as answer by Anne HeMicrosoft contingent staff Tuesday, April 5, 2016 2:41 AM
- Marked as answer by Anne HeMicrosoft contingent staff Thursday, April 7, 2016 2:17 AM
Monday, April 4, 2016 2:18 PM
All replies
-
Hi catmandu,
According to your description, you want to automatically enroll NPS certificates. Since your issue seems like the Certificate server can't receive requests and seems the issue is more related with certificate.
I would suggest turning to security forum for better help, the forum is specific for certificate.
https://social.technet.microsoft.com/Forums/windowsserver/en-US/home?forum=winserversecurity
Best Regards,
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.
Monday, March 28, 2016 5:23 AM -
Thanks for the response.
The issue resolved itself after a few days - for reasons unknown it suddenly auto-enrolled the certificate as originally expected.
- Proposed as answer by Anne HeMicrosoft contingent staff Tuesday, April 5, 2016 2:41 AM
- Marked as answer by Anne HeMicrosoft contingent staff Thursday, April 7, 2016 2:17 AM
Monday, April 4, 2016 2:18 PM -
Hi catmandu,
Glad to hear you have solved the issue.
You may mark your reply as answer, so that we can close this case.
Best Regards,
Anne
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.
Tuesday, April 5, 2016 2:42 AM