Version Affected: All
Overview
This article explains how to configure a Native Certificate Delivery realm to issue a new personal certificate every time a user enrolls, overwriting any certificate the user already has, instead of only issuing one the first time.
A realm with a Native Mode Cert Landing Page post-authentication delivers personal user certificates and automatically imports them into the certificate store through Internet Explorer. By default, if the realm detects that an authenticated user already has a valid personal certificate in their certificate store, it shows a "Congratulations" page without issuing a new certificate — this default behavior comes from the realm's Token Persistence settings.
Overwrite Existing Certificates on Every Enrollment
- In the Admin Console, go to Admin Realm > SecureAuth# > Workflow for the native certificate delivery realm, where SecureAuth# is that realm's number.
- In the Token Persistence section, set Validate Persistent Token to False and Renew Persistent Token (After Validation) to True.
- Click Save.
Users will now enroll for a new personal certificate on every successful authentication into the realm, overwriting any certificate already in their store.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.