PSS ID Number: 830858
Article Last Modified on 1/7/2004
The information in this article applies to:
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Server
SYMPTOMS
When you modify a user's name in the Active Directory directory service, the certificate on that user's smart card does not work.
CAUSE
This behavior occurs because, after you modify a user's name in Active Directory, the value in the certificate's subject alternative name field does not match the Active Directory UserPrincipleName property value.
WORKAROUND
To work around this issue, issue a new certificate when you update a user's name in Active Directory.
STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section of this article.
REFERENCES
For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
313274 HOW TO: Configure a Certification Authority to Issue Smart Card Certificates in Windows 2000
257480 Certificate Enrollment Using Smart Cards
Keywords: kbprb KB830858
Technology: kbwin2000AdvServ kbwin2000AdvServSearch kbwin2000Search kbwin2000Serv kbwin2000ServSearch kbWinAdvServSearch