Smart Card Enrollment Control (scrdenrl.dll) query 1
From: Fam (fwyen_at_yahoo.com)
Date: 02/17/04
- Next message: Fam: "Smart Card Enrollment Control (scrdenrl.dll) query 2"
- Previous message: Danish Qamar: "CertGetNameString strange error (CAPI)"
- Next in thread: Vishal Agarwal[MSFT]: "Re: Smart Card Enrollment Control (scrdenrl.dll) query 1"
- Reply: Vishal Agarwal[MSFT]: "Re: Smart Card Enrollment Control (scrdenrl.dll) query 1"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 16 Feb 2004 22:38:48 -0800
I've tested with scrdenrl.dll (Smart Card Enrollment
Control) in Windows Server 2003. It can be use to enroll
a SmartcardLogon certificate on behalf of other user.
However when come to enrollment with key archival, it
didn't work.
I've read the microsoft document "Key Archival and
Management in Windows Server 2003 (white paper)". In this
document it stated the requirements for Key Archival:
Requirements
Key Archival and Recovery using a Windows Server 2003
certificate authority has several tenical dependencies:
- Enrollment requires the CMC protocol, which is only
available in Windows XP client, Windows Server 2003
clients, and through xenroll ActiveX control in the CA Web
enrollment interface. Through the Web enrollment
interface, Windows 2000 and Windows ME may enroll for
certificates with key archival.
Above point only mention about xenroll.dll and not
scrdenrl.dll.
I have also tested to use scrdenrl.dll to enroll for
certificate with key archival but it didn't work. The
error message is:
The request is missing a required private key for archival
by the server. 0x80094804(-2146875388)
Denied by Policy Module
However when I use the xenroll.dll to do the enrollment
for the same certificate template (with key archival),
then it works.
It seems to me that scrdenrl.dll cannot support key
archival certificate enrollment. Is that correct?
- Next message: Fam: "Smart Card Enrollment Control (scrdenrl.dll) query 2"
- Previous message: Danish Qamar: "CertGetNameString strange error (CAPI)"
- Next in thread: Vishal Agarwal[MSFT]: "Re: Smart Card Enrollment Control (scrdenrl.dll) query 1"
- Reply: Vishal Agarwal[MSFT]: "Re: Smart Card Enrollment Control (scrdenrl.dll) query 1"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|