Click here to get back home

W2003 PKI: Publish certificates onto user objects in active directory

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
W2003 PKI: Publish certificates onto user objects in active directory Christoph 12-14-2005
Posted by Christoph on December 14, 2005, 1:04 pm
Please log in for more thread options
Hello
Initial position:
-Root- and Subdomain W2003, Clients XP Prof.
-W2003 PKI with a root (standalone, not ad-integrated) and an
enterprise subca (ad-integrated).
-Enrolling smartcards on behalf of idNexus
-Certificate template (encryption) is configured to publish
certificates in AD

Problem:
The smartcards with the certificates are enrolled perfectly but on the
user objects in AD there are no encryption certificates published. They
should because we need them on the user object for an encryption
software getting them there in AD.

I tried also with softcertificates (one encryption, one client
authentication) which I configured with the same checkbox on the
template "publish certificate in ad". Then I autoenrolled to some
users. But also here no certs are published onto the user obejcts.

Anybody has an idea what the problem could be?

Thank you very much!

Christoph


Posted by Saleh Matani on January 5, 2006, 9:23 am
Please log in for more thread options
Christoph schrieb:
> Hello
> Initial position:
> -Root- and Subdomain W2003, Clients XP Prof.
> -W2003 PKI with a root (standalone, not ad-integrated) and an
> enterprise subca (ad-integrated).
> -Enrolling smartcards on behalf of idNexus
> -Certificate template (encryption) is configured to publish
> certificates in AD
>
> Problem:
> The smartcards with the certificates are enrolled perfectly but on the
> user objects in AD there are no encryption certificates published. They
> should because we need them on the user object for an encryption
> software getting them there in AD.
>
> I tried also with softcertificates (one encryption, one client
> authentication) which I configured with the same checkbox on the
> template "publish certificate in ad". Then I autoenrolled to some
> users. But also here no certs are published onto the user obejcts.
>
> Anybody has an idea what the problem could be?
>
> Thank you very much!
>
> Christoph
>

Hello Christoph ,

check the Permissions of AD user objects (with ADSIEDIT.MSC) or if the
enrollment Software is logged as domain admin to be able to publish user
certificates!
try to publish a loged user certificate with mmc!

waiting for your feed back


Saleh Matani

Similar ThreadsPosted
Published Certificates in Active Directory February 9, 2006, 6:53 pm
User Security Inheritance in Active Directory May 21, 2008, 1:44 pm
sysadmin user in windows Active directory users and computers July 27, 2005, 12:31 pm
Publish the cross-certificates? July 25, 2008, 8:09 am
auditing active directory not working properly directory serviceaccess October 21, 2005, 7:47 pm
Publish Certificates in AD - parent\child domain April 4, 2006, 6:13 pm
Linking PKI directory accounts with Active Directory? February 11, 2007, 5:29 am
Active Directory December 28, 2005, 7:00 am
eap-tls without active directory November 23, 2006, 10:52 am
Active Directory May 1, 2008, 11:11 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap