Re: Certificate disappears after a few hours?



I solved it.

I think the reason why the "Domain Controller" certificate disappears is because it is superseeded by the "Domain Controller Authentication" certificate. This is stated in the "Domain Controller Authentication" template.

To make authentication work I had to activate the "RAS and IAS" template on our CA, and setup autoenrollment for it. After reboot of the NPS servers the had the new certificate and RADIUS authentication from wireless clients was successful.

Ole Thomsen


"Ole Thomsen" <ot@xxxxxxxxxxx> wrote in message news:14EEA98D-CF01-428C-A827-01B1608FE583@xxxxxxxxxxxxxxxx
I am running NPS for wireless certificate authentication on two 2008 domain controllers.

Default certificates on these servers are based on the templates "Domain Controller Authentication" and "Directory Email Replication".

However, none of these are accepted as EAP certificate in the NPS policy, but if I add the "Domain Controller" certificate everything works as expected.

My problem is that this new certificate vanishes after a few hours, and I have to enroll a new to enable user access to the wireless network.

What can cause this behaviour?

Ole Thomsen


.



Relevant Pages

  • Issuing Domain Controller certificates manually
    ... this certificate template (as well as the Computer certificate ... generating a certificate request on the domain controller). ... If you use the web interface, you will notice that these two ...
    (microsoft.public.win2000.security)
  • Re: Event ID 13 - automatic certificate enrollment error
    ... I'm having problems understanding how to set permissions. ... MMC for the certificate authority I can see the certificate templates folder ... I can see the template Domain Controller. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Event ID 13 - automatic certificate enrollment error
    ... add Domain Controllers to it and check enroll ... > MMC for the certificate authority I can see the certificate templates ... > folder and when I select it I can then see Domain Controller on the ... > manage I can see the template Domain Controller. ...
    (microsoft.public.windows.server.active_directory)
  • Autoenrollment Failure (0x80070005) - Additional help reqd.
    ... apply the fix recommended. ... One of the DCs is also a Certificate Server. ... >> has successfully obtained a 'Domain Controller' certificate. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Certificate Problem - Smart Card Logon
    ... Is your Domain Controller being issued the Domain Controller Authentication ... Authentication template which is a version 2 template for 2003 Domain ... and "Update certificates that use the certificate templates". ...
    (microsoft.public.win2000.security)