I cannot select a V2 or V3 template when enrolling for a certificate


hello,


when try enroll certificate, cannot choose modified (new) v2 certificate template enrollment website drop down list.
can navigate workstation browser or sub-ca browser (both ie 8.0) http://pkisca.mycompany.ca/certsrv , prompted login;  can login either pki\myself or pki\fzappa.  certificate error (expected, since i'm using self-signed ssl cert on iis side of things).  continue on website , can see microsoft active directory certificate services - pkisca welcome page.  click on request certificate (under select task:), brings me request certificate page.  click on advanced certificate request, brings me advanced certificate request page.  click on create , submit request ca, brings me advanced certificate request page.   click yes on web access confirmation popup (this website attempting perform digital certificate operation on behalf.), , page, again, no issues.
however, here things go awry.

problem
in certificate template dropdown list (on advanced certificate request web page) , can see following 2 items:  user and web server when log ie browser on pkisca using either myself or fzappa accounts.
what's more bizarre when log ie browser on windows 7 workstation, 2 different behaviours:

  • when log in myself, can see 4 templates: user , web server , administrator , subordinate certification authority .
  • when log in fzappa, can see 2 templates:  user , web server

*******************************************************************************************************************

*****  why can not select (or see) new certificate template i've created (see below) called web server - company ??? *****

*******************************************************************************************************************

environment setup
1.  root ca stand-alone, off-line ca running windows server 2008 r2 standard.   have no issues root ca.
2. have single domain controller installed on windows server 2008 r2 standard.  there single forest , single domain within forest.  i've setup dns services default settings (i have not in way manually modified dns after role installed).
hostname:  dc1.pki.mycompany.ca
domain:  pki.mycompany.ca
dns root domain pki.mycompany.ca
don't seem have issues domain controller or windows installation.
3.  have single subordinate ca installed on windows server 2008 r2 standard.  have additionally installed certification authority web enrollment , certificate enrollment web service role services.  iis using self-signed certificate ssl browser.  
have created new certificate template using certificate templates snap-in, local session on pkisca host.  did duplicating existing web server (windows 2000) template new template called web server - company .  selected windows server 2008 enterprise.  made no other changes , saved new template.
went certification authority snap-in, , navigated pkisca - certificate templates store.  right-click right pane , selected new - certificate template issue.  selected new certificate template list, , published pkisca ca.
have following certificate templates published on pkisca:

  • web server - company
  • directory email replication
  • domain controller authentication
  • domain controller
  • web server
  • computer
  • user
  • subordinate certification authority
  • administrator

pkisca hostname:  pkisca.pki.mycompany.ca
ca name:  pkisca
4.  have single workstation, running windows 7 home premium edition, internet explorer 8.0.7600.  there single user defined, administrative rights workstation.
5.  in domain, have defined 2 users:  myself , fzappamyself is member of domain admins , enterprise admins groups.  fzappa not assigned group in particular.  other accounts (local dc, sub-ca , workstation) default accounts.

i've managed contact microsoft directly, , answer tech support v3 templates not published web enrollment service.  can use templates through other enrollment schemes (i.e. certificate management snap-in).



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file