Smart Card Enrollment
Hello All,I am trying to setup smart card enrollment and I am having some problems. I have a 2008 Certificate Authority and have set up a Vista enrollment station. We are using ACOS5 cards from ACS. I've used the admin tool to format the cards.When I enroll for a smart card certificate, using the Microsoft Base Smart Card Cryptographic Provider, I get "The card is not the one being requested, and cannot be used for the current operation." A CSP for specific for my cards was not in the list of available CSPs.I also tried using the default CSP (Microsoft Strong Cryptographic Provider), exported the certificate (with the private key) and used the admin tool to upload the certificate to the card. When I try to use the card, Vista tells me "The card supplied requires drivers which are not present on this system. Please try another card."Any guidance on how to properly get going with the ACOS5 cards would be appreciated.Joe
December 27th, 2008 9:34am

Hi Joe,You need to load the ACS CSP middleware on the Vista workstation where you are requesting the smart card. In addition, you must either have the custom v2 certificate template set to require the ACS CSP or to use any CSP on the requesting workstation. There is no default CSP in the operating system that will work with these cards "out of the box"If you plan to use these cards on other workstations, you will need to look into licensing for the middleware to enable deployment to all relevant workstations.Brian
Free Windows Admin Tool Kit Click here and download it now
December 29th, 2008 8:40am

Turns out that ACOS5 just doesn't support x64 at all. I did try it on an x86 Vista machine, but MMC crashes when it tries to create the certificate (right after it asks for the card's pin).Can any one suggest some cards that work well with Vista/2008 x64?Thanks,Joe
January 29th, 2009 2:52am

Joe, Is it the mmc that is crashing or the ACOS5 csp? I don't know much about ACOS5, but do you know if it has any logging available? The first place to check is the application event log. You can try Infineon or Gemalto cards. I think they have out-of-box support in Vista; but you'll have to double check. Andrew
Free Windows Admin Tool Kit Click here and download it now
January 30th, 2009 5:27am

Joe, Is it the mmc that is crashing or the ACOS5 csp? I don't know much about ACOS5, but do you know if it has any logging available? The first place to check is the application event log. You can try Infineon or Gemalto cards. I think they have out-of-box support in Vista; but you'll have to double check. Andrew
January 30th, 2009 5:27am

I have been working for two weeks straight to find a compatible middleware application for the ACOS5 smart cards. Support for the ACOS5 is horrific at best. The parent company in Hong Kong is unresponsive and I haven't found an out of the box middleware app that works with Vista. Dekart has been working on a Vista login client for four years, which is a good effort but way behind the curve for implementation.At this point, I would recommend staying away from ACOS5 smart cards unless you buy ACS' readers. Trying to use and ACOS5 card with any other SC reader is a futile effort.
Free Windows Admin Tool Kit Click here and download it now
March 6th, 2009 12:37pm

Follow up to my initial post. I have been working with a sales engineer from ACS on this issue and it looks like the CSP drivers aren't getting loaded into memory due to a registry issue. I have one of the CryptoMate USB tokens and two of the ACOS5 smart cards. The SE from ACS hs been very helpful thus far and I have sent log file dumps to him to assist with the issue. Once I get the solution mapped out, I will post a follow up message here. ACS' SE and I have been working across a lot of time zones, which makes the communication cycle take a long time.
March 13th, 2009 6:28am

Follow up to my initial post. I have been working with a sales engineer from ACS on this issue and it looks like the CSP drivers aren't getting loaded into memory due to a registry issue. I have one of the CryptoMate USB tokens and two of the ACOS5 smart cards. The SE from ACS hs been very helpful thus far and I have sent log file dumps to him to assist with the issue. Once I get the solution mapped out, I will post a follow up message here. ACS' SE and I have been working across a lot of time zones, which makes the communication cycle take a long time. Hi Blades1987, I am trying to get the ACOS5 cards working with Server 2008 R2 x64. Did you get anywhere with ACS support? Thanks, Tony
Free Windows Admin Tool Kit Click here and download it now
January 27th, 2011 12:28pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics