Active Directory User Object certificate store to personal certificate store

From: Rob McShinsky (List_at_mcshinsky.com)
Date: 02/25/05


Date: Fri, 25 Feb 2005 13:19:26 -0500

Is there a way to move AD published certs to from the Active Directory User
Object cert store to the Personal cert store so that these will follow a
user around from computer to computer so they can be utilized by
applications. At the current time we are not looking at autoenrolling
certificates because we want to have users create High Security certificates
that will require a password before the cert is used for client
authentication. I can see the certs in the AD User Object cert store for
the user logged in but they are not accessable from IE, at least with my
current knowledge. This is where our current PKI test application is. Is
there a GPO setting that will make these accessable within the Personal
store? Is there a way to have an application directly reference the AD User
Object cert store? Is ther another programatic/scripting way to utilize
these certs? Thanks for your guidance on this subject.

Rob McShinsky