I cannot select a V2 or V3 template when enrolling for a certificate
hello,
when try enroll certificate, cannot choose modified (new) v2 certificate template enrollment website drop down list.
can navigate workstation browser or sub-ca browser (both ie 8.0) http://pkisca.mycompany.ca/certsrv , prompted login; can login either pki\myself or pki\fzappa. certificate error (expected, since i'm using self-signed ssl cert on iis side of things). continue on website , can see microsoft active directory certificate services - pkisca welcome page. click on request certificate (under select task:), brings me request certificate page. click on advanced certificate request, brings me advanced certificate request page. click on create , submit request ca, brings me advanced certificate request page. click yes on web access confirmation popup (this website attempting perform digital certificate operation on behalf.), , page, again, no issues.
however, here things go awry.
problem
in certificate template dropdown list (on advanced certificate request web page) , can see following 2 items: user and web server when log ie browser on pkisca using either myself or fzappa accounts.
what's more bizarre when log ie browser on windows 7 workstation, 2 different behaviours:
- when log in myself, can see 4 templates: user , web server , administrator , subordinate certification authority .
- when log in fzappa, can see 2 templates: user , web server
*******************************************************************************************************************
***** why can not select (or see) new certificate template i've created (see below) called web server - company ??? *****
*******************************************************************************************************************
environment setup
1. root ca stand-alone, off-line ca running windows server 2008 r2 standard. have no issues root ca.
2. have single domain controller installed on windows server 2008 r2 standard. there single forest , single domain within forest. i've setup dns services default settings (i have not in way manually modified dns after role installed).
hostname: dc1.pki.mycompany.ca
domain: pki.mycompany.ca
dns root domain pki.mycompany.ca
don't seem have issues domain controller or windows installation.
3. have single subordinate ca installed on windows server 2008 r2 standard. have additionally installed certification authority web enrollment , certificate enrollment web service role services. iis using self-signed certificate ssl browser.
have created new certificate template using certificate templates snap-in, local session on pkisca host. did duplicating existing web server (windows 2000) template new template called web server - company . selected windows server 2008 enterprise. made no other changes , saved new template.
went certification authority snap-in, , navigated pkisca - certificate templates store. right-click right pane , selected new - certificate template issue. selected new certificate template list, , published pkisca ca.
have following certificate templates published on pkisca:
- web server - company
- directory email replication
- domain controller authentication
- domain controller
- web server
- computer
- user
- subordinate certification authority
- administrator
pkisca hostname: pkisca.pki.mycompany.ca
ca name: pkisca
4. have single workstation, running windows 7 home premium edition, internet explorer 8.0.7600. there single user defined, administrative rights workstation.
5. in domain, have defined 2 users: myself , fzappa . myself is member of domain admins , enterprise admins groups. fzappa not assigned group in particular. other accounts (local dc, sub-ca , workstation) default accounts.
i've managed contact microsoft directly, , answer tech support v3 templates not published web enrollment service. can use templates through other enrollment schemes (i.e. certificate management snap-in).
Windows Server > Directory Services
Comments
Post a Comment