I’ve configured ADCS to install user and computer certificates via GPO. With those certs I can do EAP-TLS authentication from the machines to a Clearpass RADIUS server. This is a good thing.
But I’m trying to have users download user certificates for non-domain computers from http:///certsrv. They can download a cert, but it doesn’t get placed in the ‘Personal’ certificate store on the client machine, but in the ‘Active Directory User Object’ store. EAP-TLS authentication fails. Upon further examination, it appears that the certificate does not have the private key downloaded with it. The certificates installed via GPO do have the private key. Without the private key on the computer, EAP-TLS will always fail.
How do I get ADCS to allow the private key to be downloaded via the web interface? The ‘User’ certificate template has the box checked to allow this. I even created a new certificate template, and ensured that the option to allow private key downloading was enabled.
Ideas?
Thank you!