|Applies To||RSA SecurID Passage 3.5.1 Client|
Microsoft Windows XP Professional SP1
|Issue||Certificate enrollment through Microsoft MMC using RSA SecurID Passage 3.5.1|
Certificate enrollment fails when attempted through the Microsoft MMC with the error "request failed the parameter is incorrect"
|Resolution||To correct this issue, perform the following steps:|
1. Open Certificate Templates (as admin)
2. Right click on smartcard logon
4. Name your template, check "publish in AD"
5. Go to request handling tab and change purpose to 'signature and smartcard logon'
6. Set minimum key size to 1024(MUST BE 1024!)
7. Click CSPS button, click radio button "requests must use one of the following CSPS"
8. Check "passage enhanced crypto provider" and click OK
9. Go to security tab. You may now either add groups of users and check the Enroll/Autoenroll options, or add in domain users to have it attempt to auto enroll all users in the domain
NOTE: You must have RSA CSP installed or else this will fail for those individuals
10. Click OK
11. Go to Certificate Authority on your CA (as admin)
12. Right click "certificate templates", choose "new" then "certificate template to issue", then select the template you just created
13. Repeat on any other CAs in enterprise
|Legacy Article ID||a20610|