One Unified Global Perspective
Communications with a Global Perspective
Home
Intro
Contact Us
Voice over IP
PBX Solutions
Services
Support
Glossary
Open Source
Blog
Forum

WebMail





2007 May 07 - Mon

User Certficate Auto Enrollment

With my 802.1x test setup, machine certificates were being sent to domain machines with no problem, but user certificates were not showing up.

In the group policy object, right on the container housing the users that needed certificates, I set the auto-enrollment settings. For some reason things weren't being inherited from the domain default policy. The group policy container is User Configuration -> Windows Settings -> Security Settings -> Public Key Policies -> Autoenrollment SEttings. The 'Enroll Certificates Automatically' needs to be checked along with it's two subsidiary check boxes.

The following command serves as a manual refresh of the policy:

gpupdate /target:user

Enrollment will take several minutes. Running the certmgr.msc mmc snap-in will allow one to check that the certificate has arrived in the Personal -> Certificates store.

The Application Event Log will contain success/failure status for the auto-enrollment.

I also found out from an troubleshooting auto-enrollment article, that domain users without email addresses will not auto-enroll. They don't need an actual email box, just an entry in the email attribute in Active Directory.

As further reference, Microsoft has an article on How Autoenrollment Works. There are other related and helpful articles in the same library section.



Blog Content ©2008
Ray Burkholder
All Rights Reserved
ray@oneunified.net
(441) 505 7293
Available for Contract Work
Resume

RSS: Click to see the XML version of this web page.

View Ray 
Burkholder's profile on LinkedIn
technorati
Add to Technorati Favorites



May
Su Mo Tu We Th Fr Sa
   
7
   


Main Links:
Monitoring Server
SSH Tools
QuantDeveloper Code

Special Links:
Frink

Blog Links:
Sergey Solyanik
Marc Andreessen
HotGigs
Micro Persuasion
... Reasonable ...
Chris Donnan
BeyondVC
lifehacker
Trader Mike
Ticker Sense
HeadRush
TraderFeed
Stock Bandit
The Daily WTF
Guy Kawaski
J. Brant Arseneau
Steve Pavlina
Matt Cutts
Kevin Scaldeferri
Joel On Software
Quant Recruiter
Blosxom User Group
Wesner Moise
Julian Dunn
Steve Yegge

2007
Months
May




Mason HQ

Disclaimer: This site may include market analysis. All ideas, opinions, and/or forecasts, expressed or implied herein, are for informational purposes only and should not be construed as a recommendation to invest, trade, and/or speculate in the markets. Any investments, trades, and/or speculations made in light of the ideas, opinions, and/or forecasts, expressed or implied herein, are committed at your own risk, financial or otherwise.