can I digitally sign a document with a certificate store in active directory?


we have ca , have configured group of test users have user certificates autoenrolled them , stored in ad.  have made private key exportable , cert valid client authentication , code signing.  when open certificate mmc snap in, can verify cert there, not show option when try digitally sign word document.  have tried save cert file , import personal certificate store, still not show cert when try sign document.

i did notice when exported cert file, did not ask me if wanted export private key.  have verified template have "allow private key exported?" enabled.

from i have read, only public key gets stored in ad allowing other members of domain trust signed documents.  went ahead , made gpo generate digital signature each time user logs onto machine if don't have one.  if i'm wrong, , cert stored in ad should allow user sign doc pc in domain, never figured out how make work.


Microsoft Office  >  Word IT Pro Discussions



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file