Re: Windows 2000 Certificate Services Management / auto renew

From: Vishal Agarwal[MSFT] (vishala_at_online.microsoft.com)
Date: 01/12/04

  • Next message: Roy: "How to stop Users from saving or downloading unto the desktop"
    Date: Mon, 12 Jan 2004 09:26:26 -0800
    
    

    You can use ICertView COM interface to look into CA's database and find the
    certificates that are about to expire.

    For User certificate Auto-renewal, you should use V2 templates and have
    atleast Windows XP as the client base.

    Thanks,
    Vishal [MSFT]

    -- 
    This posting is provided "AS IS" with no warranties, and confers no rights
    "Fred Dunn" <dunn@uthscsa.edu> wrote in message
    news:98C77791-5725-4351-A465-9FF05A8582AA@microsoft.com...
    > We have a Windows 2000 CA in place and we are piloting a smartcard
    authentication project now. All appears to work fine but no notice is given
    to the certificate holder before their cert expires. Is there a COM object
    that I can use to script a parse of the Issuing CA's edb file for certs that
    are about to expire? CAPICOM does not "see" smartcard certs except those on
    the local system when the smartcard is inserted. When I perform a search
    with the CAPICOM object for ACTIVE_DIRECTORY_USER_STORE it only returns the
    certs issued for encryption, signing, etc. but never returns an EKU of
    smartcard logon.
    > At the same time is there a method of auto-renewal of smartcard certs?
    This is a "show stopper" for our pilot. We have seen some features that may
    work in Windows 2003 Certificate Services but don't want to have to go to
    that extreme if not necessary. Any ideas are welcome.
    >
    > Thanks,
    > Fred Dunn
    > University of Texas Health Science Center
    

  • Next message: Roy: "How to stop Users from saving or downloading unto the desktop"

    Relevant Pages

    • Re: Cant install Thawte Certificate using Account Settings
      ... They expire in 2013. ... The two Thawte CA's show ... I try to select a certificate, and "Choose" just make the dialog go ... X509 expire in 2020-- different certs, ...
      (microsoft.public.mac.office.entourage)
    • Re: Problem with CryptSignMessage use in GINA DLL
      ... Except that smartcard based certificates are not associated with a user (at ... certs on smartcards is to eliminate the password). ... The certificate is read from the smartcard correctly ... >> postings give no clue as to a solution. ...
      (microsoft.public.platformsdk.security)
    • RE: Relative Security Provided by Cached Domain Credentials?
      ... So when a user logs on the w2k terminal using a smartcard + pin no (rather ... If it does then EFS ... profile currently logged on for the private certificate. ...
      (Focus-Microsoft)
    • Re: ADFS and Certificate Services
      ... ADFS even allows you to do client certificate ... Joe Kaplan-MS MVP Directory Services Programming ... We just want to be able to give out certs to our own ... sub-CA on the internet for employees to access remotely to get certs. ...
      (microsoft.public.windows.server.active_directory)
    • Re: ADFS Proxy Cert issue
      ... know the command line for requesting a proper client certificate though. ... you would start getting these certs from the CA that you will ... FSP setup better. ...
      (microsoft.public.windows.server.active_directory)