NDES
2 TopicsHow do I assign a certificate template to MSCEP??
I setup a issuing CA and NDES server for non-Windows wi-fi device certificate authentication. I also made a certificate template called "SCEPTemplate" that was a duplicate of the Workstation Authentication template. Here are the permissions of the template I created: When the device requests a certificate, the CA assigns this certificate from the wrong template: If I disable the IPSec (Offline request) template, then the CA will error and not assign a certificate. this is what I see in Event viewer: It looks like the IPSec (Offline request) template is somehow the default certificate template for MSCEP. In the guide I used to configure the server, it said to change the "GeneralPurposeTemplate" registry key to SCEPTemplate, which I did: Does anyone have any ideas to get past this? I did find this guide which may mention something about this but doesn't have a solution. https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/ndes-security-best-practices/ba-p/28326191.8KViews0likes0CommentsNDES certificate problem
Hello, I set up the environment used with this guide: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert Everything seems ok, NDES check tool (https://docs.microsoft.com/en-us/troubleshoot/mem/intune/verify-ndes-configuration) did not find any error. However, on NDES server, C:\Program Files\Microsoft Intune\NDESPolicyModule\Logs\NDESPlugin.log shows the following errors: Calling VerifyRequest ... Sending request to certificate registration point... Failed to retrieve client certificate. Error -2147024809 Exiting VerifyRequest with 0x80070057 On NDES server, Application log for NetworkDeviceEnrollmentService, doesnt show any error/warning How next? Thank you for your help! KR, ZoltanSolved6.2KViews0likes5Comments