Mombu the Microsoft Forum sponsored links

Go Back   Mombu the Microsoft Forum > Microsoft > Certificate Renewal minimum requirements
User Name
Password
REGISTER NOW! Mark Forums Read

sponsored links


Reply
 
1 8th August 11:23
mc
External User
 
Posts: 1
Default Certificate Renewal minimum requirements



Hi,

What are the minimum requirements to renew a smart card user certificate
stored on a smart card?

Is it necessary to give the user "enroll" permissions to renew an existing
certificate ?
I configured a copy of the smart card user template to allow renewal if an
existing valid certificat exists.

Thanks
MC
  Reply With Quote


  sponsored links


2 8th August 11:23
david cross [ms]
External User
 
Posts: 1
Default Certificate Renewal minimum requirements



yes, they will still need autoenroll permission, I think we have an example
for usingf existing cert and auto-renewal in this paper:

auto-enrollment:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx


--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com
  Reply With Quote
3 8th August 11:24
mc
External User
 
Posts: 1
Default Certificate Renewal minimum requirements


David, thanks for that input.

Is the auto-enroll permission enough, or must the user be granted the
"enroll" permissions too ?
In the MS do***ents you can find statements, that when autoenroll
permissions are granted user always must have enroll permissions too.

The problem would be when enroll permissions are granted, users would be
able to enroll smart card user certificates by themselves. It only should be
possible to enroll smart card user certificates by a couple of admins who
own an enrollment agent certificate.

Thx,
Mario
  Reply With Quote
4 19th August 09:33
brian komar
External User
 
Posts: 1
Default Certificate Renewal minimum requirements


In article <eps2fPDuEHA.3860@TK2MSFTNGP09.phx.gbl>, seaedsit@hotmail.com
says...

The solution is to use two certificate templates. The first, for initial
enrollment only allows the couple of admins to enroll on behalf of the
user. This is accomplished by limiting permissions to the enrollment
agents and to require the certificate request agent OID in the signing
certificate. This certificate can include a custom application policy
OID designated as the "Company" smart card

Then you can create a renewal certificate that:
- supercedes the initial certificate
- enables Read, Enroll, and Autoenroll perms to *all* smart card holders
- Requires that the request be signed with an application policy OID,
the "Company" smart card OID.

HTH,
Brian


Ths
  Reply With Quote
Reply


Thread Tools
Display Modes




Copyright © 2006 SmartyDevil.com - Dies Mies Jeschet Boenedoesef Douvema Enitemaus -
666