joining a computer to the domain via certificate.

  • Thread starter Thread starter ariel
  • Start date Start date
A

ariel

Hi

There is a way of joining computers to a domain by using
certificate,
I have a computer with XP client and I would like to join
it to 2000 domain.

I am trying to do so by using a certificate which I
downloaded for that user that have Administration
permissions. (By using the user name and password I can
add the computer to that domain.)

All the certificates are downloaded from Microsoft CA.
I tried almost all the certificate templets that I know
exist, but with no success.

For example: I am using a SmartCard user or SmartCard
logon certificates and I get the error message:

"logon failure:unknown user name or password"




The process looks like this:
I am choosing the certificate instead of using user name
and password.



My question is:

Do you know how can I add a computer to a domain by using
only a certificate?
What kind of a certificate must it be?

Thanks In Advance,
Ariel Malinovsky.
 
Hi, ariel -

I'm doing quite a bit of work with smartcard
authentication for my employer. My first guess would be
that the certificate doesn't have a username associated
with it in AD, but there are many things that could be
causing problems here - too many to list in a simple
message.

I'd like to refer you to a couple of articles that'll
help get you started -

Troubleshooting Windows 2000 PKI Deployment and Smart
Card Logon
http://www.microsoft.com/technet/treeview/default.asp?
url=/TechNet/prodtechnol/windows2000serv/support/trblshoot
/smartct.asp

and

Guidelines for Enabling Smart Card Logon with Third-Party
Certification Authorities
http://support.microsoft.com/support/kb/articles/Q281/2/45
..ASP

good luck!
 
Back
Top