EFS and Certificate Services

From: Rschraeger (Rschraeger_at_discussions.microsoft.com)
Date: 08/24/05


Date: Wed, 24 Aug 2005 06:11:04 -0700

Ok I'm hopping that this is a bug in the software but in reality its realy
bugging me.

I created a Enterprise Root CA with a Enterprise Subordinate CA for issuing
EFS certificates. The Root CA is offline. The client, a 2000 pro machine,
is in the Domain and the user is a normal user of the domain (domain users)
and is in the administrators group on the local machine.

When the user encryptes a file a certificate from the Subordinate CA is
issue. I check the thumbprint of the file and the certificate which matched.
 So far..so good. Then 5 minutes or so later a second certificate for EFS is
issued from the CA. This certificate has a different thumbprint and is never
used for EFS. Why the two certs? and how can I get only one!

PLEASE HELP!!!

-- 
RS
MCSE, MCP +I MCP


Relevant Pages

  • Enterprise Root Certification Authority not trusted
    ... Yesterday installed Enterprise Root and Enterprise Subordinate CA on ... Windows 2003 standard in Windows 2000 active directory domain. ... certificate cannot be verified up to a trusted certification ...
    (microsoft.public.windows.server.security)
  • Re: Forest, Domain, Certificate, CA, IAS/Radius, Issues
    ... All servers are Windows Server 2003 with service pack 2. ... Only DomainA has the "Enterprise Root CA" and DomainB_DC1 is a subordinate ... the Certificate Renewal Wizard, I get "The certificate request failed ... How do I manually request a Domain Controller certificate from DC2? ...
    (microsoft.public.windows.server.networking)
  • Non domain member, IPSec VPN Certificate
    ... We have an Enterprise Root CA installed, running on Windows 2003 ... How do I get a valid IPSec VPN cert onto his computer? ... I need to duplicate the certificate (if my ...
    (microsoft.public.isa.vpn)
  • Re: untrusted domain in certificate
    ... Enterprise Root CA server in my ... > decide weather I want trust it or not. ... That happens because your client computer doesn't trust your CA. ... get/install the CA certificate to your client computer. ...
    (microsoft.public.win2000.security)
  • Re: Cert Server - Changed Enterprise CA
    ... Certificate Request Setup Wizard asks which certification authority it ... New Enterprise Root CA ... So I removed it and readded it, and it looks like I get a new Cert. ... Before you create an automatic certificate request, ...
    (microsoft.public.win2000.active_directory)