Hi

I have a CA Enterprise (2003) in a 2003 Active Directory Domain. I have installed the SCEP-Add on to enroll a certificate to a PIX 525 (Ver. 6.32). When I make a request, from the PIX console, to enroll a certificate, it is rejected by the CA with this message: denied by policy module
I had read that there is a different configuration with "SCEP-Add on" in a CA Enterprise. I need to kno
which are the steps needed to configure SCEP-Add on in a CA Enterprise. The "SCEP-Add on" release note tells that these steps are described in Windows 2003 Resource Kit Documentation, but i didn't found them

Thanks in advanc
Paolo

Re: CA Enterprise SCEP-Add on by David

David
Wed May 05 07:26:22 CDT 2004

which version of SCEP are you using? the version that first shipped with
the windows server 2003 reskit had some issues in supporting Cisco VPN
clients. This is the latest version which includes an HTML help file. have
you looked in the CA application log to see why the reqyest was denied?

http://www.microsoft.com/downloads/details.aspx?displaylang=en&familyid=9f306763-d036-41d8-8860-1636411b2d01


--


David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

"Paolo" <anonymous@discussions.microsoft.com> wrote in message
news:66146868-2578-464B-AC88-CD60A08546E5@microsoft.com...
> Hi,
>
> I have a CA Enterprise (2003) in a 2003 Active Directory Domain. I have
installed the SCEP-Add on to enroll a certificate to a PIX 525 (Ver. 6.32).
When I make a request, from the PIX console, to enroll a certificate, it is
rejected by the CA with this message: denied by policy module.
> I had read that there is a different configuration with "SCEP-Add on" in a
CA Enterprise. I need to know
> which are the steps needed to configure SCEP-Add on in a CA Enterprise.
The "SCEP-Add on" release note tells that these steps are described in
Windows 2003 Resource Kit Documentation, but i didn't found them.
>
> Thanks in advance
> Paolo



Re: CA Enterprise SCEP-Add on by David

David
Thu May 06 10:49:54 CDT 2004

The Application Event Log on the CA machine may have more details.

In the Failed Requests view, the Request Status Code column and the Request
Disposition Message column may also have more information.


--
David B. Cross [MS]

--
This posting is provided "AS IS" with no warranties, and confers no rights.

http://support.microsoft.com

"Paolo" <anonymous@discussions.microsoft.com> wrote in message
news:5DD0AB26-24AC-4D2A-8E89-F3E5553BEFA7@microsoft.com...
> Thanks for your reply,
>
> The scep-addon is the correct version.
> In the MMC Certification Authority snap-in, in the "Failed Requests"
folder I can
> see in the "Request Disposition Message" column this description : "Denied
by Policy Module".
>