I am trying to create a custom certificate template based off of the Smartcard User template with a Windows Server 2008 Enterprise subordinate CA. I am using the subordinate CA because the root CA is not on the domain. Here are my steps so far:
- I duplicated the Smartcard User template for the new template I'm trying to create
- I set the appropriate validity period and CSP
I figure this is all I should need to do as my organization does not use issuance policies or anything. However, when I try to enroll a cert on behalf of a user, the template does not show up. When the "Show all templates" box is checked, the template appears with the following error message: "The requested property value is empty. You do not have permission to view this type of certificate."
I have looked through the Microsoft libraries and googled for information on this error, however it does not appear to be well-documented. Any input would be greatly appreciated. Thank you!