Click here to get back home

Smart card enrollment issues

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Smart card enrollment issues verukins 04-29-2008
Posted by verukins on April 29, 2008, 8:23 pm
Please log in for more thread options
Hi all,
I am trying to enroll some smart cards with the following
setup

Reader - Gemalto PC Twin USB (Old Name = Gempc twin usb)
Cards - Gemalto Classic TPC IS White PVC (Old name = GemSafeXpresso
32K)

CA - Windows 2008 Enterprise Root CA
Enrollment station - Vista SP1

th intent is to use these cards for remote access via TSGateway.

Problem 1 - When trying to create another certificate template by
duplicating the "smart card logon" template, that template is not
available from the enrollment station. I have modified the issuance
requirements as per one of the technet articles below, but with no
sucess.

Problem 2 - When i try to issue from the standard "smart card logon",
i am prompted to insert my smartcard, however the certificate goes
straight into the personal store and does not prompt me for a PIN.

The gemalto troublshooting tools seem to indicate that my reader and
smartcard are all good.

I've been looking the the following articles (some of which are geared
towards win 2003)

http://207.46.196.114/windowsserver/en/library/99827b56-216a-475b-a7e9-84c8d4c749de1033.mspx?mfr=true
http://technet2.microsoft.com/windowsserver/en/library/5229033e-232b-4f91-9f86-0cbbd7cfc5a81033.mspx?mfr=true
http://support.microsoft.com/kb/313629
http://support.microsoft.com/kb/922706

Can anyone assist ?

Posted by Brian Komar \(MVP\) on April 30, 2008, 2:06 am
Please log in for more thread options
Some questions:
1) What SKU are you using of Windows Server 2008. The CA must be running on
Enterprise Edition to enable v2 or v3 certificate templates.
2) Not sure what is happening on that one
Can yhou provide more details on how you are performing the request?
Brian

> Hi all,
> I am trying to enroll some smart cards with the following
> setup
>
> Reader - Gemalto PC Twin USB (Old Name = Gempc twin usb)
> Cards - Gemalto Classic TPC IS White PVC (Old name = GemSafeXpresso
> 32K)
>
> CA - Windows 2008 Enterprise Root CA
> Enrollment station - Vista SP1
>
> th intent is to use these cards for remote access via TSGateway.
>
> Problem 1 - When trying to create another certificate template by
> duplicating the "smart card logon" template, that template is not
> available from the enrollment station. I have modified the issuance
> requirements as per one of the technet articles below, but with no
> sucess.
>
> Problem 2 - When i try to issue from the standard "smart card logon",
> i am prompted to insert my smartcard, however the certificate goes
> straight into the personal store and does not prompt me for a PIN.
>
> The gemalto troublshooting tools seem to indicate that my reader and
> smartcard are all good.
>
> I've been looking the the following articles (some of which are geared
> towards win 2003)
>
>
http://207.46.196.114/windowsserver/en/library/99827b56-216a-475b-a7e9-84c8d4c749de1033.mspx?mfr=true
>
http://technet2.microsoft.com/windowsserver/en/library/5229033e-232b-4f91-9f86-0cbbd7cfc5a81033.mspx?mfr=true
> http://support.microsoft.com/kb/313629
> http://support.microsoft.com/kb/922706
>
> Can anyone assist ?


Posted by verukins on April 30, 2008, 2:41 am
Please log in for more thread options
Hi Brian,
1) yep, 2008 Enterprise (i ran into that problem back in
2003 and wont be making that mistake again!)
2) I am performing the request though my vista SP1 mmc.
(ie open an mmc, add the certificates snap in, right click on personal
and follow the tree through to "enroll certificate on behalf of
another user" and then follow the bouncing ball.)

Posted by verukins on May 1, 2008, 6:09 pm
Please log in for more thread options
Jsut an update...

I have also now tried the same process with a win 2k3 enterprise CA
via the web page entrollment...

Having the same issue, where the reader etc is recognised, but the
card cannot be found when inserting it.

Posted by Brian Komar \(MVP\) on May 2, 2008, 10:25 am
Please log in for more thread options
What card are you using
What middleware have you installed
What version of middleware are you running
What happens when you try and use the cards native tools to inspect the
card?
Brian

> Jsut an update...
>
> I have also now tried the same process with a win 2k3 enterprise CA
> via the web page entrollment...
>
> Having the same issue, where the reader etc is recognised, but the
> card cannot be found when inserting it.


Similar ThreadsPosted
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart card reader and card supplier in Australia May 5, 2008, 10:37 pm
Re-initialize smart card June 3, 2005, 8:34 am
Smart Card - two readers December 8, 2006, 8:28 am
smart card offline logon July 7, 2005, 9:02 am
Base Smart Card CSP Update December 7, 2005, 3:12 pm
Q: Seconary certificate on a smart card August 5, 2006, 6:24 am
Question Regarding Smart Card Deployment September 12, 2007, 2:16 pm
Using a flash drive instead of a smart card. April 28, 2008, 1:25 am
Issuing secondary cert. to smart card June 3, 2005, 8:08 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap