Smartcard Logon not enabled

We're running ADCS on a domain joined WS2008RS server.  Autoenrollment has been enabled (via GPO) for both the computer and user configurations (as verified through rsop.msc).
The domain controllers have enrolled in the following certificate templates:
Kerberos Authentication
Domain Controller
Domain Controller Authentication
The test user has enrolled in the Smartcard Logon template.
Yet when trying to logon via smartcard on the host I receive an error like "account is not enabled for smart card login".
I then proceed to check the box on my user account in AD which states "require smartcard for interactive login" and also enable the same setting on my client system (Security Options\Interactive Logon: Require smart card).
My logon is still denied but states I should check with your administrator to ensure smartcards are enabled for login. 
I've also enabled the workstation authentication template which my test system has successfully enrolled in.
Anyone been through this or have some pointers where to look?  We're now digging around in a hay stack.
Thanks!

We have had this problem a few times - solved by re-issuing the Domain Controller Authentication cert.
    On DC, opened
mmc.
    Click
File, Click Add/Remove Snap-in.
    Select
Certificates, click Add, then select Computer account.
    Expand
Certificates (Local Computer), right-click Personal, click
All Tasks, and then click Request New Certificate.
    In the
Request Certificates page select Domain Controller Authentication
See if that works for you!

Similar Messages

  • Server0 getting down and logon not possible ( error in license check)

    Hi Guys,
    I rebooted my SAP server and after that server0 is in disabled mode, well both the boxes seems to be green but the server0 node in disable mode as if it is maintained by some parameter and I have changed it, which is not the case, also there is no log with dev_server0 since then. I have followed 723909 note and also copied the parameters of a running server but didn't get success. Also when I am trying to login through SAPGUI its giving me error " Logon not possible( error in license check)" while the license is already installed.
    dev_w0 log says
    M Wed Sep 01 14:42:14 2010
    M  *** ERROR => sap license, no valid license found [likeyapi_w.c 2260]
    M  *** ERROR => wlikey_check_webas: There is a permanent license key for "NetWeaver_ADA" in the system but it has never been checked successfully. In this situation a temporary license key mustn't be installed. [sliclikey.c  1314]
    M  *** ERROR => The temporary license key for NetWeaver_ADA could not be installed [likeyapi_w.c 2305]
    SAP ECC 6.0 release 700
    DB: MaxDB
    OS: Win2k3 server
    Please help.
    Regards
    Mridul Gupta

    License issue is resolved but server0 node is still in disable status while the instances shows green, I checked dev_jcontrol log and found :
    [Thr 2168] [Node: server0] java home is set by profile parameter
         Java Home: C:\j2sdk1.4.2_25-x64
    [Thr 2168] JStartupICheckFrameworkPackage: can't find framework package E:\usr\sap\W6Q\DVEBMGS12\exe\jvmx.jar
    JStartupIReadSection: read node properties [ID123322550]
    -> node name          : server0
    -> node type          : server
    -> node execute       : no
    -> jlaunch parameters :
    -> java path          : C:\j2sdk1.4.2_25-x64
    I think the node execute sud be yes, I just wanted to know how I can enable this.
    Regards,
    Mridul Gupta

  • SSO logon not possible; logon tickets not activated on the server

    When I am on RWB
    1)  click "component monitoring" ->"display all"
    2) click "CCMS"
    I get a popup says:
    "SSO logon not possible; logon tickets not activated on the server"
    I find some threads about this on SDN but they are about
    EP. My case is PI7.0SP08.
    Please advise how to overcome this issue?
    Thanks w/ points.
    Message was edited by:
            jennifer lee

    hI,
    do you have the follwoing in our SXMB_ADM if not add them.
    SXMB_ADM->IntegrationEngine configuratin-> edit the speicifc configuratin then add the follwoing
    Category:RUNTIME Parameters: logging Value:1
    If its done. check this alos...whether your browser settings will accept the cookies or not. for SSO logon ticket method you need to have cookies accepted by our browser so check it. in internet page slect TOOLS ->internet options then ckeck for cookies settings.
    How to Enable Single-Sign-On for XI 3.0 at:
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/69d95112-0d01-0010-8297-fa31feea26e0
    /people/alexander.bundschuh/blog/2007/01/16/principal-propagation-in-sap-xi
    http://help.sap.com/saphelp_nw2004s/helpdata/en/5c/b7d53ae8ab9248e10000000a114084/content.htm
    regards
    manoj kumar

  • Request Smartcard Logon certificates for more than 2 years from Certificate Authority

    Dear all,
    I have setup a Certificate Services in a Windows Server 2008 R2 domain and I request certificates via the CA webpage
    http://ipofdomainserver/certsrv using the SmartCard logon custom template.
    The problem is that my certificates are only valid for 2 years even though when I created my custom Smartcard logon I selected for validity period 5 years. 
    I read in documentation that issued certificates cannot have a greater validity than the root that signed them.
    What and where I should modify to be able to request certificates from the template for more years than standard 2 ?
    Ps: WINSC-CA is valid for 5 years. Should I generate a new WINSC-CA ? How ?

    I was successfully able to create a root CA for 20 years, issued a certificate and login using smartcard using the following procedure:
    1. I increased the CA lifetime to 20 years by using this link http://www.expta.com/2010/08/how-to-create-certificates-with-longer.html
    Created the file CAPolicy.inf in %SYSTEMROOT% with following content
    [Version]
    Signature=”$Windows NT$”
    [certsrv_server]
    RenewalValidityPeriod=Years
    RenewalValidityPeriodUnits=20
    2. Renew CA root using this guide  https://technet.microsoft.com/en-us/library/cc780374(v=ws.10).aspx
    Console Root -> Certification Authority -> select domain -> Right click -> All Tasks ->
    Renew CA certificate
    3. Delete from Console Root -> Certificates (local computer) -> Trusted Root Certification
    Authority -> Certificates the *WINSC-CA that has the previous lower validity, and from 
    Certificates (local computer) -> Personal, the *WINSC-CA that was lower validity
    4. I performed a reboot here
    5. Change in Console Root -> Certificate Templates -> Smartcard Logon Custom Template (my custom duplicate template) -> Properties -> Validity 10 years
    6. Change in registry HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CertSvc\Configuration\<CAName>\ValidityPeriod
    to value 10 for 10 years.
    7. Request a new certificate from CA webpage http://ipofdomain/certsrv and let the webpage write it to
    smartcard (I was making sure there is no other certificate on the smartcard)
    8. Try to log in. At this point it should throw an erorr that smartcard logon is not supported for this
    account type. This is becuase we need to enroll it again for domain authentication
    9. Console Root -> Certificates (local Computer) -> Personal -> Right click -> All Tasks ->
    Request new Certificate -> Next -> Active Directory Enrollment -> Next -> Select Domain Controller Authentication -> Enroll -> Finish.
    Now you should be able to login using your smartcard and 10 years generated certificate.
    Though I have a problem at step 3, after CA server reboots the *WINSC-CA certificate with lower
    validity is restored automatically, but the certificates are generated for 10 years.
    What am I doing wrong ? How can I delete the lower validity root CA ?

  • Mercury CUDA not enabling when using NVIDIA GeForce GTX 285 on Apple Mac Pro after Mavericks install

    Been using the same setup since CS5 with the Mercury CUDA running perfectly. After recent upgrade of OS X to 10.9 Mercury CUDA is no longer available and only lets me run with the OpenGL or software options. Im using a NVIDIA GeForce GTX 285 for apple computers. Here are the results for the GPUSniffer program in the latest Premiere Pro 7.1.0 files. The LAST line make me chucle because it the first on the list of supported card in the "cuda_supported_cards.txt" file. Anybody else seen this?
    --- OpenGL Info ---
    Vendor: NVIDIA Corporation
    Renderer: NVIDIA GeForce GTX 285 OpenGL Engine
    OpenGL Version: 2.1 NVIDIA-8.18.27 310.40.05f01
    GLSL Version: 1.20
    Monitors: 1
    Monitor 0 properties -
       Size: (0, 0, 1920, 1080)
       Max texture size: 8192
       Supports non-power of two: 1
       Shaders 444: 1
       Shaders 422: 1
       Shaders 420: 1
    --- GPU Computation Info ---
    Found 1 devices supporting GPU computation.
    OpenCL Device 0 -
       Name: GeForce GTX 285
       Vendor: NVIDIA (Apple platform)
       Capability: 1.2
       Driver: 1
       Total Video Memory: 1024MB
       * Not enabled by default because it did not match the named list of cards.

    found a link from a couple of days ago on a creative cow forum post one of the poster saying they are from adobe stating this
    Re: Mercury Playback Engine MacPro
    by Peter Garaway on Nov 12, 2013 at 9:49:16 am
    Hi Wendell,
    Sorry for the inconvenience. NVIDIA is currently working on drivers that support CUDA on Mavericks 10.9 with some of the older NVIDIA cards such as the GTX 285 and the Quadro 4800.
    For others interested, the Quadro 4000, K5000 and GTX 680 ect... work with CUDA in 10.9.
    Best,
    Peter Garaway
    Adobe
    Premiere Pro
    I have latest CUDA drivers, so i guess i am just waiting till a proper update that have the fixes to support my card.

  • Why is the 'Choose icon...' button in the Options tab of the field property dialog box not enabled?

    I am using Adobe Acrobat Professional XI running on Windows 8.
    This “feature” has been bugging me for some time now. I remember it happening when I used Acrobat 9 Professional (Windows XP) and it is still happening in Acrobat XI Professional. I think I figured out a situation when I can reproduce this “feature” conistently and I hope someone fixes this.
    Try the following and see what happens:
    1. Acrobat Professional is not open.
    2. Launch Word and start editing a document (or some other authoring tool that can generete PDF document).
    3. After editing the document, generate a PDF version of the document.
    4. Launch Acrobat Professional and edit the PDF document generated in 3.
    5. Add a button.
    6. View the button's properties.
    7. Change the Fill Color property in the Appearance tab to none.
    8. Change the Layout in the Options tab to Icon only.
    Now here is what bugs be. Shouldn’t the 'Choose Icon ...' button be enabled? It is not enabled after step 8. It is possible that 'Choose Icon ...' button is enabled for some of you. I this case, it would be nice if at least one of you who experience the same bug say so in this thread so that Adobe doesn't think I am sending them on a wild goose chase.
    I can enable it by selecting a different tab and then returning to the Options tab. A similar thing happens when reverting back from 'Icon only' to 'Label only' but I am not sure how to reconstruct a scenario for this one.
    Here is the dialog box for one instance when I noticed the bug.
    Regards,
    John

    You're right, it has been that way for a long time. I've never bothered reporting it as a bug since it's simple enough to deal with, but reporting it would be a reasonable thing to do.

  • BitLocker not Enabled on HP ElitePad 1000 G2

    I have an HP ElitePad 1000 G2 that I am using MDT to apply our 8.1 x64 Update image.  This task sequence works fine on all other systems on which it has run.  On the ElitePad, when the task sequence completes, BitLocker is not enabled.
    Running manage-bde-status returns:
    Disk volumes that can be protected with
    BitLocker Drive Encryption:
    Volume C: [OSDisk]
    [OS Volume]
        Size:                 115.58 GB
        BitLocker Version:    2.0
        Conversion Status:    Used Space Only Encrypted
        Percentage Encrypted: 100.0%
        Encryption Method:    AES 128
        Protection Status:    Protection Off
        Lock Status:          Unlocked
        Identification Field: Unknown
        Key Protectors:
            TPM
    If I look in the BitLocker applet on the control panel, it says "OSDisk (C:) BitLocker is waiting for activation"
    the ZTIBDE.log just stops at:
    Attempting to intiate ProtectKeyWithNumericalP@ssword
    <Message containing password has been suppressed>
    A successful system shows:
    Attempting to intiate ProtectKeyWithNumericalP@ssword
    Success protecting Key with numerical p@ssword
    If I click Turn on BitLocker in the control panel applet or run the following commands:
    manage-bde -protectors -add c: -recoverypassword
    manage-bde -on c: -recoverypassword
    The recovery key protector is created and uploaded to AD and BitLocker shows as enabled.
    Any ideas to why this is happening?

    after some more investigation, I found the following article
    http://netecm.netree.ch/blog/Lists/Posts/Post.aspx?ID=80 and adding the registry key referenced in the article fixed the issue.

  • Drill by is not enabled in BO 4.0 WebI report

    Hi,
    In one of my report I have to do Drill by. But when I right click on the dimension I am able to see only Drill Down that is enabled.
    Drill by is not enabled. Please let me know how to enable Drill By in BO 4.0 WebI report.
    Thanks in advance
    Lavanya

    Hai
    Enable drill mode right in BOE 4.0
    http://www.sdn.sap.com/irj/scn/web-intelligence40-elearning-all
    http://www.sdn.sap.com/irj/scn/index?rid=/library/uuid/d0e40af9-0d6a-2e10-b58a-c4ecde511a6e
    Thank u

  • Firefox plays video, but no sound. when I type about:plugins in location bar, it shows the firefox default plugin is not enabled. When I look at my plugins, it says it is enabled. I have uninstalled 3.6 and re-installed with the same result.

    firefox plays video, but no sound. when I type about:plugins in location bar, it shows the firefox default plugin is not enabled. When I look at my plugins, it says it is enabled. I have uninstalled 3.6 and re-installed with the same result. Why do I have no sound. Computer plays I-tunes and all other sounds, just no web browser sounds.

    Glad you seem to have sorted things out.
    The warning about the warranty is light hearted, I think at one stage it warned "here be dragons" but also intended to make us think as it warns that making changes may produce problems.

  • Why firefox 3.6 downloads all of the files again after restartarting the browser from a website if the "clear history when Firefox closed" is not Enabled?

    We have a corporate website, we officially support FF3, FF4, IE8 and IE9. Our web site is quite big, so we really need browser caching, first time page load is around 15 seconds. With files in the cache getting new page is less than a second.
    Everything works perfect except with FF3. With FF4, IE8, IE9 if we are on the website, clicking everywhere is fast, the page is in the cache. If we restart the browser, it is still fast, it loads files from the cache.
    But with FF3 we have a problem. Every time we restart the browser, it is loading the files again from the server, instead of using the local cache (checked with Firebug). I can reproduce the problem anytime, it is the same with every FF3 instances. I double checked, the "clear history when Firefox closed" option is not enabled.
    Could you advise please how to use the local cache either after browser restart?
    Thank you!
    Chris

    Just read that the default memory storage on FF is set to 5 mbs. You can up that by clicking on tools, advanced and overriding the default and set it to 50 mbs (if you use lots of tabs) or 10 mbs (if you use just a few).
    I open a blank tab and clear the cache periodically, while I am working. I can have several tabs open and watch videos on Youtube, by doing this. Have you cleared your cache?
    Since I have an older computer, I've also used CCleaner for years. I use it often, but always before signing off. You can get it free...search for CCleaner, download from Pirifoam free. I didn't change any of the settings and it clears crap left behind from uninstalling programs, clears all browsers at once of: cookies, history, passwords, etc. I love it!
    I had freezing, before using the "open blank tab, clear the cache" thing. Now I have no problems. Plus, as I said...you can change the default memory usage for FF and that should help too.
    Hope this helps! Good luck! :)

  • I can't use home sharing because it says Bonjour is not enabled.  So I went to administrative tools and started it.  Restarted my computer and home sharing still isn't working

    I can't use home sharing because it says Bonjour is not enabled.  So I went to administrative tools and started it.  Restarted my computer and home sharing still isn't working

    I have also tried repairing Bonjour in adminstrative tools and still a no go! Frustrated!!! Looking for another idea

  • Remote Desktop Connection - cannot proceed because authentication is not enabled

    Hello,
    I try to connect via RDP from a Windows Server 2008 R2 to another 2008 R2 Server.
    I always get the error message.
    The connection cannot proceed because authentication is not enabled and the remote computer requires than authentication be enabled to connect.
    On the target machine the Remote Settings are set to:
    Allow connections from computers running any version of Remote Desktop.
    Firewall is disabled on both servers.
    Therefor I do not understand why I get an error message, that authentication is required.
    The target box is a nearly fresh syspreped machine with all current Hotfixes installed.
    I already found a lot of people having that problem by using XP (old RDP client), but no one seems to have this problem when connecting from 2008 R2 to 2008 R2.
    Thank you very much in advance for every hint.
    BR
    Matthias

    Hi Matthias,
    First I would like to confirm if you have deployed RDS (Remote Desktop Services) and you got the error, if so, please check this option
    TS Configuration, >> RDP-Tcp Properties >> change the Security Layer to "Negotiate"
    Then Recycle the TS Gateway service.
    Refer to:
    Unable to connect to Server using the Remote Web Workplace (RWW) Small Business Server 2008
    If this issue has nothing to do with RDS, and I suppose you used the cmd "mstsc" to remote access. This issue may also occur because of the version of mstsc, please make sure it has been upgraded to the new version.
    In addition, Did you have another newer server available like Server 2012? So we can test and try to use Server 2012 to remote access Server 2008 R2, and check if the issue persists.
    If there is anything else regarding this issue, please feel free to post back.
    If you have any feedback on our support, please click here.
    Best Regards,
    Anna Wang
    TechNet Community Support

  • Since updating to Firefox 3.6.15, I can no longer print coupons from SmartSource. The error message is that Java is not detected. The check box is longer showing in the Options/Content of this version of Firefox, so I can not enable it.

    # Question
    Since updating to Firefox 3.6.15, I can no longer print coupons from SmartSource. The error message is that Java is not detected. The check box is longer showing in the Options/Content of this version of Firefox, so I can not enable it.

    Same PC as I used to post the question. When I go to the "plug in check" page, it shows I am up to date and it is not disabled.
    Java(TM) Platform SE 6 U24
    Next Generation Java Plug-in 1.6.0_24 for Mozilla browsers 1.6.0.24

  • Got error: Location Code is not enabled in the XML Gateway Server

    Hi,
    When I perform Compliance rule screening on GTM - Globel Trade Management,that I defined GTM as an Trading Partner on EBS R12.1.3,
    GTM can send response to EBS,but I see the following error message via Transaction Monitor on EBS workflow:
    [The Standard:OAG, Transaction Type:ITM , Transaction SubType:EXPORT_COMPLIANCE and Location Code GTM6.2 is not enabled in the XML Gateway Server. Pls check your Setup.]
    On EBS,I defined an ITM Partner for GTM,named 'GTM6.2',according to the document created by you: ITM Setup.doc
    and I also finished the following steps:
    1. ITM Application Users
    2.ITM Partner Service Types
    3.ITM Parameter Setup
    4.Order Type Creation: ITM Only
    5.Customer Creation: create a customer named 'GTM6.2', also enter 'GTM6.2' as EDI Location
    6.Define Transactions on XML Gateway as following:
    <Header>:
    Party Type: Customer
    Transaction Type: ITM
    Transaction Sub Type: EXPORT_COMPLIANCE
    <External Transactions (Lines)>:
    Standard Code: OAG
    External Transaction Type: ITM
    External Transaction Sub Type: EXPORT_COMPLAINCE
    Queue: APPLSYS.ECX_IN_OAG_Q
    7.Define Trading Partners on XML Gateway as following:
    <Header>:
    Trading Partner Type: Customer
    Trading Partner Name: GTM6.2
    <Trading Partner Details>:
    Transaction Type: ITM
    External Transaction Type: ITM
    External Transaction Sub Type: EXPORT_COMPLAINCE
    Map: WSHITEIN
    Source Trading Partner Location Code: GTM6.2 (same as the value what defined in EDI Location for customer)
    I think the combination of External Transaction Type, External Transaction Subtype, Standard Code,Source Trading Partner Location Code
    should be existing once done above steps, I have no idea why the error prompted.
    Does someone can tell how to trace the error?
    Thanks,
    Rambler

    user12254038 wrote:
    Can you send any supporting documents on ITM Setup? My client is implementing ITM for the first time and I wanted to know more details on how it works in R12.1.3 version of EBS?Oracle International Trade Management (ITM) Partner Integration: Specifications [ID 572524.1]
    International Trade Management Integration [ID 259691.1]
    How Can I Tell if International Trade Management is Installed or Not? [ID 742539.1]
    What are the Required Setups for International Trade Management (ITM) Flows in Shipping Execution? [ID 782861.1]
    What Patches Provide the Latest Fixes and Enhancements for ITM Adapter? [ID 465122.1]
    How to Generate Debug Information From ITM Adapter for XML Processing [ID 738925.1]
    How to Generate Debug File for International Trade Management (ITM) [ID 1294853.1]
    Thanks,
    Hussein

  • Why SLFM is not enabled for Macbook 13" Aluminum late 2008 model?

    Hi All,
    Does anyone know why SLFM is not enabled for Macbook 13" Aluminum late 2008 model?
    I just found this out after I installed bootcamp and Windows 7 on my Macbook 13" with P8600 2.4Ghz CPU 2GB RAM and 250G HDD after more than a year of using it.
    After I installed the CPU monitoring widget on Windows 7 and CPUZ, I noticed that the lowest Freq that my Macbook operates even with <5% CPU load is only 1.5Ghz and VID @1.0V.
    I installed Coolbook on OSX to confirm what I saw on Windows. I was surprised that SLFM is not visible in Coolbook which is the same result I got from Windows 7 CPU monitoring widget and CPUZ.
    I checked with our local Mac support and they got the same results for all of Macbook 13" Aluminums late 2008 model. SLFM is not visible on Coolbook which means, it is not enabled.
    I tried to install Coolbook on my wife's Macbook Pro 13" 2010, which has the same spec, P8600 2.4Ghz CPU and 250G HDD. The only difference is the memory which is 4GB RAM. There, SLFM is enabled and works just fine, running at 798Mhz @0.875V.
    Can anyone please help confirm if this is really the case for Macbook 13" late 2008 model?
    Because I checked the Intel P8600 Datasheet and SLFM should always be enabled. Otherwise, it will affect battery life as well as long term reliability of the CPU.
    I would appreciate if the Macbook and Macbook Pro owners in this forum can help confirm using Coolbook the status of SLFM in your own Macbooks. You may use any other tool in checking the SLFM and share it with us if you believe it is more reliable and better than Coolbook. Thanks.
    Message was edited by: jespada

    BTW, Here is what I got from Coolbook for comparison. As you can see the late 2008 Macbook has no SLFM info.
    Legend:
    SLFM - Super Low Freq Mode
    LFM - Low Freq Mode
    HFM GV - High Freq Mode (Geyserville/Speedstep)
    HFM - High Freq Mode
    Macbook 13" Aluminum late 2008 P8600 2.4Ghz 2GB RAM 250GB HDD
    Freq VID
    SLFM -- --
    LFM 1596Mhz 1.0000V
    HFM GV2 1862Mhz 1.0500V
    HFM GV1 2128Mhz 1.1000V
    HFM 2394Mhz 1.1375V
    Macbook Pro 13" Aluminum 2010 P8600 2.4Ghz 4GB RAM 250GB HDD
    Freq VID
    SLFM 798Mhz 0.8750V
    LFM 1596Mhz 1.0000V
    HFM GV2 1862Mhz 1.0500V
    HFM GV1 2128Mhz 1.1000V
    HFM 2394Mhz 1.1375V
    Message was edited by: jespada
    Message was edited by: jespada

Maybe you are looking for

  • How to install coldfusion 8 on windows xp pro sp3

    hi I  installed coldfusion 8 (standart or multiserver) with any error but browse coldfusion admin panel I getting some error like  The Macromedia application server(s) are unreachable. how to solve this problem firewall turn off antivirus software no

  • Creative Cloud Does Not Start - Help!

    If anyone from Adobe is watching this.  I was considering switching from Aperture to Lightroom CC.  I was able to install the trial and it works fine.  However, all of a sudden, Adobe Creative Cloud App will not run.  The icon appears for a moment th

  • Completed forms appearing blank

    I created a fillable form using Adobe Acrobat X Pro, Version 10.0.1. Users download the online form from a web page (often using the Reader app on the iPad) and e-mail it to me. They are advised to e-mail the "flattened" version of the forms, but I a

  • Fascinate video will not load into iphoto on macbook

    my mp4 video opens in quicktime player.  I "saved as" in quicktime to a .mov file. neither the mp4 or the .mov file will load into iphoto. iphoto error message says, "could not be imported, unrecognizable format." I tried a new SD card and new video

  • HARDWARE PROBLEM - BLACK SCREEN

    My iphone screen turned black all of a saden. I tired to restart and get into recovery mode but its something with the hardware. What can it be? It started flircking and then turned off. The iphone is work but the screen doesnt respond.