Microsoft Windows Vista
RSA Smart Card Middleware
RSA SID 800 Authenticator
RSA SecurID 800 Authenticator
Microsoft Internet Explorer 7.0
issues with enrolling for an RCM Administrator/Vettor certificate in Vista using Sid800
After clicking submit on the admin enrollment page "<INSTALL-DIR>/WebServer/enroll-server/request-msie-admin.xuda ", the page did not change.
errors in the middleware logs:
2008-12-17 22:06:41.469 1056.1280 [E] HRESULT error encountered: 0x80100030
Microsoft wants the non-export key flag enabled for the certificate/key.
1. Install the middleware in Vista
2. Resign Admin CA cert to have basic constraints
a. Sign from another CA that allows Basic PKIX-Compliant CA profile:
i. Ensure that the CA that you sign from allows another subordinate CA = verify the Path Length Constraint of signing CA first, otherwise Admin cert verification will fail.
ii. Set path length constraint to 0 for new Admin CA cert.
b. Restart sdir.
c. Re-sign, using self (Admin CA) and keep existing extensions.
d. Restart sdir
3. Trust System CA so the enrollment website is trusted
4. Add the enrollment website to the Trusted Sites in IE
a. Allow Unsigned ActiveX and Scripts to run for Trusted Sites ? Set to Prompt
5. Update Admin enrollment xuda file with new version (RCM 6.8 build 516 or higher)
6. Uncomment appropriate lines in enrollment new xuda page
Enroll for Admin cert using SID 800, you will receive many prompts related to running scripts and activex controls due to the trusted sites settings.
a. Select 1024
b. Select Smart Card provider
c. Select protect private key = yes
d. Enter SID 800 PIN
e. Wait for about a minute
8. Approve Cert
9. Visit cert download link
10. Click Install Root CA cert (Unless you have already trusted the Admin CA), need to manually select trusted root CAs as storage container.
11.
Solution How to successfully enroll for a certificate with IE7 on Microsoft Vista
BZ 117807
Related Articles
How to successfully enroll for a certificate with IE7 on Microsoft Vista 10Number of Views Unable to enroll to the KRA from a Cisco VPN Client on Linux 5Number of Views Unable to enroll certificate using SCEP auto-vetting from Cisco VPN Concentrator 25Number of Views Re-enrolling for a certificate 6Number of Views User is not enrolled for any of the allowed identity confirmation authentication methods error during RSA Authentication M… 31Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process