can I digitally sign a document with a certificate store in active directory?


we have ca , have configured group of test users have user certificates autoenrolled them , stored in ad.  have made private key exportable , cert valid client authentication , code signing.  when open certificate mmc snap in, can verify cert there, not show option when try digitally sign word document.  have tried save cert file , import personal certificate store, still not show cert when try sign document.

i did notice when exported cert file, did not ask me if wanted export private key.  have verified template have "allow private key exported?" enabled.

from i have read, only public key gets stored in ad allowing other members of domain trust signed documents.  went ahead , made gpo generate digital signature each time user logs onto machine if don't have one.  if i'm wrong, , cert stored in ad should allow user sign doc pc in domain, never figured out how make work.


Microsoft Office  >  Word IT Pro Discussions



Comments

Popular posts from this blog

directory stack

After enabling Windows Server 2012 R2 DHCP Failover Getting Packet dropped because of Client ID hash mismatch

WMI Repository 4GB limit - Win 2003 Ent Question