<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1873" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-06-15T18:52:21+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1873</id>
<entry>
<author><name><![CDATA[OverkillTASF]]></name></author>
<updated>2015-06-15T18:52:21+01:00</updated>
<published>2015-06-15T18:52:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7426#p7426</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7426#p7426"/>
<title type="html"><![CDATA[Re: ADCS certificate enrollment, native Windows 7 functional]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7426#p7426"><![CDATA[
<div class="quotetitle">Tom2 wrote:</div><div class="quotecontent"><br />OpenSC does not support CMC format.<br /></div><br /><br />Selecting PKCS didn't make a difference.<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />For self- enrollment use the PIV MANAGER GUI.<br /></div><br />This ended up working, just ran into trouble initially because I was using the Display Name and not the internal name of the certificate template.<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />you can edit the guy to leave just 1 button and rename it &quot;give me a smartcard i don't know what I am doing&quot;<br /></div><br />I assume editing the GUI is an appdev activity? I am just a lowly server engineer. <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />I assume you have a workstation where the user goes and self-enroll right ? just have him insert the NEO and use the PIV MANAGER GUI.<br /></div><br />Not today. We're still trying to determine how this process is going to work out.<br /><br />Thanks Tom2, you did provide useful information and I think I can at least write up documentation on using PIV Manager.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3708">OverkillTASF</a> — Mon Jun 15, 2015 6:52 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-05-13T09:09:26+01:00</updated>
<published>2015-05-13T09:09:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7314#p7314</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7314#p7314"/>
<title type="html"><![CDATA[Re: ADCS certificate enrollment, native Windows 7 functional]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7314#p7314"><![CDATA[
OpenSC does not support CMC format.<br /><br />For self- enrollment use the PIV MANAGER GUI. It is extremely simple and you can edit the guy to leave just 1 button and rename it &quot;give me a smartcard i don't know what I am doing&quot;<br /><br />I assume you have a workstation where the user goes and self-enroll right ? just have him insert the NEO and use the PIV MANAGER GUI.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Wed May 13, 2015 9:09 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[OverkillTASF]]></name></author>
<updated>2015-05-12T19:02:50+01:00</updated>
<published>2015-05-12T19:02:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7305#p7305</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7305#p7305"/>
<title type="html"><![CDATA[Re: ADCS certificate enrollment, native Windows 7 functional]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7305#p7305"><![CDATA[
Thanks. I had seen this before (which is how I managed to change the PIN), and it certainly provides sufficient information for me to import a Windows certificate, but I was hoping that users would be able to do this themselves without any additional software. I apologize for not knowing the names of the subsystems involved, but with previous smart cards, users could go to the web interface on our issuing CA and request a smart card certificate. Their inserted smart card would show up, and they'd have to enter their PIN (Or administrator PIN) to enroll and get the private keys loaded on their smart card. With the Yuibkey, I get the popup shown in the attached file.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3708">OverkillTASF</a> — Tue May 12, 2015 7:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-05-12T09:28:18+01:00</updated>
<published>2015-05-12T09:28:18+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7302#p7302</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7302#p7302"/>
<title type="html"><![CDATA[Re: ADCS certificate enrollment, native Windows 7 functional]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7302#p7302"><![CDATA[
<!-- m --><a class="postlink" href="https://developers.yubico.com/PIV/Introduction/">https://developers.yubico.com/PIV/Introduction/</a><!-- m --><br /><br /><!-- m --><a class="postlink" href="https://developers.yubico.com/PIV/Tools/YubiKey_PIV_Manager.html">https://developers.yubico.com/PIV/Tools ... nager.html</a><!-- m --><br /><br /><!-- m --><a class="postlink" href="https://developers.yubico.com/yubico-piv-tool/Windows_certificate.html">https://developers.yubico.com/yubico-pi ... icate.html</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Tue May 12, 2015 9:28 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[OverkillTASF]]></name></author>
<updated>2015-05-11T19:09:49+01:00</updated>
<published>2015-05-11T19:09:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7295#p7295</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7295#p7295"/>
<title type="html"><![CDATA[ADCS certificate enrollment, native Windows 7 functionality?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1873&amp;p=7295#p7295"><![CDATA[
I have received a Yubikey NEO to pilot a deployment for admin accounts in an Active Directory domain. I was hoping I could deploy these with minimal installation of additional software on users' machines.<br /><br />ADCS provides a URL, <!-- m --><a class="postlink" href="https://certificateauthority.domain.int/CertSrv">https://certificateauthority.domain.int/CertSrv</a><!-- m -->, where users can enroll, using their AD credentials, for certificates. Smart card functionality is included here. I have enabled CCID on the NEO, yet when it comes time to enroll for a certificate, Windows reports that my NEO is read-only. I have used the PIV manager to reset the PIN and management PIN but don't seem to see an option to unlock it so that Windows' native Smart Card services can enroll for a new smart card cert.<br /><br />Am I missing something?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3708">OverkillTASF</a> — Mon May 11, 2015 7:09 pm</p><hr />
]]></content>
</entry>
</feed>