"No certificate templates could be found..." error using web enrollment on Win2k8 R2 Enterprise SubCA
hi folks,
i have installed online issuing ca running on win2k8 r2 enterprise, , installed web enrollment role service on it.
i have duplicated two computer certificate templates (computer & web server) on our dc's, modified them as win2k3 templates, made changes , saved them, published them on ca selecting new -> certificate tempate issue. templates have read , enroll permissions set domain admins and domain computers (my account domain admin). can enroll them using certificates mmc.
when connecting https://myca.mydomain.com/certsrv however, page loads. click on 'request certificate', 'create , submit request ca'. see warning indicating website attempting perform digital certificate operation on behalf, click yes. after doing so, error:
"no certificate templates found. not have permission request certificate ca, or error occurred while accessing active directory."
i have spent 2 hours searching on error , found @ least 50 people complaining of this, no real solutions. here have tried no success:
1) http://support.microsoft.com/kb/811418. references solution, hasn't worked anyone. string values , cases same me.
2) enabled ssl on certsrv website.
3) set authentication on certsrv site enable integrated authentication , disabled anonymous authentication.
4) created separate application pool running under network service set certsrv application run under it.
i should note exact same condition occurred in lab install, rather waste time trying fix in lab, went ahead production install, experience same problem, apparently web enrollment is broken out of box on 2k8 r2 enterprise.
does have idea how working advertised? help,
ian
ok, have found reason this.
when configure certificate templates, on subject name tab of template have choice how supply subject name in certificate request.
if select 'build active directory information' , choose parameter supplied list, not able use web enrollment , continue generate 'no certificate template found...' error.
if select 'supply in request', have access these (and these) templates after connecting web enrollment service.
simple stupid. fellows,
ian
Windows Server > Security
Comments
Post a Comment