Problem with WLAN IAS certificate enrollment

Problem with WLAN IAS certificate enrollment

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Problem with WLAN IAS certificate enrollment Randy Smith 05-16-2008
Posted by Randy Smith on May 16, 2008, 11:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
-Group policy set to allow autoenrollment
-IAS/DC's members of new security group
-Certifcate template set to allow enroll and autoenroll for newly created
security group
-Both IAS/DC's have been rebooted since adding to new group
-Domain controller certs have been issued to both IAS servers
-Selected automatically enroll certs in Certificates MMC.

I have done this a few times now over the past four days...certs are not
being issues to the IAS servers for WLAN auth. There are no errors in the
application log on the IAS servers or the CA server.

Any ideas on how to get this cert issued to both IAS servers?



Posted by Brian Komar \(MVP\) on May 16, 2008, 4:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Have you added the Domain COntrollers group to the Certsvc_DCOM_ACCEss
(something like that) group in the domain.
See the SP1 readme notes for more details
Brian

> -Group policy set to allow autoenrollment
> -IAS/DC's members of new security group
> -Certifcate template set to allow enroll and autoenroll for newly created
> security group
> -Both IAS/DC's have been rebooted since adding to new group
> -Domain controller certs have been issued to both IAS servers
> -Selected automatically enroll certs in Certificates MMC.
>
> I have done this a few times now over the past four days...certs are not
> being issues to the IAS servers for WLAN auth. There are no errors in the
> application log on the IAS servers or the CA server.
>
> Any ideas on how to get this cert issued to both IAS servers?
>
>


Posted by Randy Smith on May 19, 2008, 1:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks Brian for the response.

I found this group on my CA server as a local security group. The everyone
group was already a member but I added the domaon controllers group anyway.
I have rebooted one of my DC's to update the group membership and requested
a cert once again. It almost seems like the request is not getting to the CA
server. There is no errors or any information at all about the request in
either the DC's (ISA's) server logs or the CA server logs about the request.
But...I can request a cert from a desktop and the cert is created nearly
immediately.

The difference...the only one I can see...is the certificate template. I
created this template on the CA server and have given the appropriate
security permissions to the appropriate groups. I've also checked the
settings of the template three times...they all are correct. I've even
deleted the template and recreated it. No help.

Any more ideas are greatly appreciated.

> Have you added the Domain COntrollers group to the Certsvc_DCOM_ACCEss
> (something like that) group in the domain.
> See the SP1 readme notes for more details
> Brian
>
>> -Group policy set to allow autoenrollment
>> -IAS/DC's members of new security group
>> -Certifcate template set to allow enroll and autoenroll for newly created
>> security group
>> -Both IAS/DC's have been rebooted since adding to new group
>> -Domain controller certs have been issued to both IAS servers
>> -Selected automatically enroll certs in Certificates MMC.
>>
>> I have done this a few times now over the past four days...certs are not
>> being issues to the IAS servers for WLAN auth. There are no errors in
>> the application log on the IAS servers or the CA server.
>>
>> Any ideas on how to get this cert issued to both IAS servers?
>>
>>
>



Similar ThreadsPosted
Web Certificate Enrollment security problem March 15, 2006, 2:57 am
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:33 pm
Certificate Enrollment API: Request on behalf of another user February 13, 2008, 9:02 pm
Certificate Web Enrollment (Server 2003 and Vista) November 14, 2008, 12:16 pm
Publishing a Certificate Authority Enrollment site using SSL + ISA 2004 May 18, 2006, 5:04 pm
Certificate Enrollment on behalf of others on a W2003 Standard Server June 18, 2008, 8:02 am
Problem with certificate authority January 27, 2006, 9:03 am
pfx certificate chain problem March 21, 2006, 6:35 am
Problem in Certificate Authority February 23, 2007, 4:09 am
WLAN & Radius Setup October 18, 2005, 11:02 am

The site map in XML format XML site map

Contact Us | Privacy Policy