Version Affected: All
Overview
Enrolling for a native X.509v3 certificate can fail with the following error:
0-Certificate Request Error: Please close out your web browser and try again. If problem persists, contact help desk for assistance.
There are multiple potential causes:
- See Cause 1 - The appliance's clock is off by five minutes or more
- See Cause 2 - The private key has become corrupted
- See Cause 3 - The realm delivers a machine key, but the user's profile lacks the necessary Active Directory privileges
- See Cause 4 - After a domain migration, the user's profile lacks the privileges needed to access the certificate store
- See Cause 5 - Internet Explorer shows this error because the domain isn't trusted
These causes are not related, so a fix for one cause will not resolve the others.
In this article
- Cause 1: Appliance Clock Is Off by Five Minutes or More
- Cause 2: The Private Key Has Become Corrupted
- Cause 3: User's AD Profile Lacks Privileges to Receive a Machine Key
- Cause 4: User's Profile Lacks Certificate Store Access After a Domain Migration
- Cause 5: Internet Explorer Does Not Trust the Domain
Cause 1: Appliance Clock Is Off by Five Minutes or More
If the appliance's clock is off by five minutes or more, the appliance may be unable to retrieve the certificate from the SecureAuth cloud.
Resolution 1:
Verify the time on the appliance and, if necessary, configure NTP time synchronization.
Cause 2: The Private Key Has Become Corrupted
The private key has become corrupted, and the browser is unable to access it.
Resolution 2:
Raise a Support Case with SecureAuth Support to resolve the private key issue.
Cause 3: User's AD Profile Lacks Privileges to Receive a Machine Key
The realm is configured to deliver a machine key, but the user's Active Directory profile does not have the privileges necessary to place that key into the certificate store.
Resolution 3:
Either assign the necessary privileges to the user's Active Directory profile, or configure the realm to only assign a personal certificate instead of a machine key (under Workflow > Product Configuration, set the IE / PFX / Java Cert Type field accordingly).
Cause 4: User's Profile Lacks Certificate Store Access After a Domain Migration
After a domain migration, the user's profile does not have the privileges necessary to access the certificate store.
Resolution 4:
Note: All of the certificates in the certificate store must be deleted to resolve this issue. Export any certificates you want to keep before continuing.
- Go to the user's private key storage directory: %APPDATA%\Microsoft\Crypto\RSA (for roaming profiles, %APPDATA%\Roaming\Microsoft\Crypto\RSA).
- Delete the contents of the subfolder named after the user's SID (for example, S-1-5-21-2807450274-1270290436-441385562-1183).
- Confirm the permissions on that folder are set correctly for the user's account.
Cause 5: Internet Explorer Does Not Trust the Domain
Internet Explorer shows this error when the domain isn't trusted by the browser.
Resolution 5:
Add the domain to Internet Explorer's Local Intranet or Trusted Sites zone, under Tools > Internet Options > Security.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.