Jump to content

Recommended Posts

Posted

Has anyone had any luck with these and issuing certs from an on-prem two tier PKI to devices?

 

I can get the google one working perfectly, issuing user certificates to devices which then allows them to move to EAP-TLS for WiFi, and subsequently radius accounting pushed per-user to my firewall. However the google option uses the challenge password in NDES. When you install the InTune cloud certificate connector, it changes the way MSCEP works and the challenge password no longer works, so google devices stop receiving certificates.

 

Tearing my hair out with this one.

 

Even with the InTune connector installed, and ignoring the fact it breaks the Google one, i can't get it to issue certificates like i do with the Google one. Event logs have a bunch of 4003 information events, followed by 4005 error events which contain a "500 (Internal Server Error)." in them.... and i can't find a solution to this. Information online often relates to an older version of the intune cloud connector too. I've run a powershell script from microsoft called "Validate-NDESConfiguration.ps1" and that seems clear, all bar one error saying "Cannot find path 'HKLM:\SOFTWARE\Microsoft\Cryptography\MSCEP\Modules\NDESPolicy' because it does not exist." but i can't find any information as to why that would be, or what should be there.

 

So two separate issues really, any suggestions?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...