Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Enroll on behalf of no certificates available

$
0
0

Trying to get Smart Card Authentication setup.

Using a dedicated AD account called eagent, verified security is read and enroll for certificate templates.

  1. Installed CA on Windows 2008 R2 - Domain Controller
  2. Issued Certificate Template: Enrollment Agent
  3. Managed Templates, Duplicate Smartcard Logon, picked Server 2003 Enterprise, General tab: validity 5 years, and changed display name; Request Handling: Signature and smartcard logon; Issuance Requirements: 1 authorized signature, Application Policy type required in signature, Application policy-Certificate Request Agent.
  4. Issued Certificate Template: My Smartcard Logon
  5. From enrollment station (eagent logged on): Installed Enrollment Agent is Personal>Certificates store. Status: Succeeded
  6. From enrollment station (eagent logged on): Personal>Certificates, All Tasks, Advanced Operations, Enroll on Behalf of..., click Next twice, when I Browse for Select Enrollment Agent Certificate I get:

No certificate available

No certificatates meet the application...

Click Ok to continue

I have been back thru all settings all day, I am completely stumped.


Michael Maxwell


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>