Re: Enroll smart cards for different domain

From: Hans Walder (hans.walder_at_pointag.net)
Date: 09/17/03


Date: Wed, 17 Sep 2003 19:19:01 +0300


By the way, we are using Windows Server 2003 Native Mode and Windows XP
Professional Workstation.

Thanks to all,
Hans

"Hans Walder" <hans.walder@pointag.net> wrote in message
news:50fd01c37d1d$590db520$a501280a@phx.gbl...
> Hi everyone,
>
> We have the following test enviroment:
>
> Domain A
> - Domain Controller
> - Enterprise Certificate Authority (member of domain A)
>
> Domain B
> - Domain Controller
>
> And both domains trust each other.
>
> I can enroll smart cards for users from domain A.
>
> But is it also possible to do it for users from domain B?
> Or do we have to have our own CA for each domain?
>
> Small Hint: When I create a folder and want to add a user
> to the security tab I can choose users from both domains
> but if I enroll a smart card I can only choose them from
> domain A.
>
> Is this because the CA is only trusted to Domain
> Controller A but not do Domain Controller B?
>
> Does someone have any experiences on that?
>
> Thank you all,
> Hans
>
>



Relevant Pages

  • Re: Blank Forest Functional Level - Unable to fix
    ... to a domain controller. ... promote the new server with Windows Server 2003x64 R2 to a domain controller ... The domain functional level was Windows Server 2003. ... Server 2003 however the forest functional level is blank. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Blank Forest Functional Level - Unable to fix
    ... to a domain controller. ... promote the new server with Windows Server 2003x64 R2 to a domain controller ... The domain functional level was Windows Server 2003. ... Server 2003 however the forest functional level is blank. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Blank Forest Functional Level - Unable to fix
    ... I would start looking very closely at all DCs to verify that the same DC is set for the PDC master. ... I promoted a Windows Server 2003 SP1 server to a domain controller. ... Anyway, you could be running into something odd when raising the forest functional level and even though it isn't required for R2, I will offer a command line mechanism to do it that will kick out an error message that can be used to work out the issue. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Blank Forest Functional Level - Unable to fix
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... You need to do a forest prep to prepare the schema for R2 prior to adding an R2 Domain Controller. ... Anyway, you could be running into something odd when raising the forest functional level and even though it isn't required for R2, I will offer a command line mechanism to do it that will kick out an error message that can be used to work out the issue. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows NT 4.0 to Windows 2003 AD migration, why two windows 2003 DCs?
    ... except that I do not want to upgrade any pdc/bdcs. ... consider the method you describe a better method than to use ADMT? ... > introduce a Windows Server 2003 Domain Controller into a ... >>another domain controller for failover. ...
    (microsoft.public.windows.server.migration)

Quantcast