Symptoms
- An attempt to launch a published resource using SAML is failing with the error "The user name or password is incorrect".
- EnrolServer.log contains the following errors:
[I 6D/00000025/T0E40/P0BEC] 15-02-21 12:16:35 - No valid certificate for user user-1 (CN=user-1,OU=...) was found. A new certificate needs to be enrolled
[W 6D/00000025/T0E40/P0BEC] 15-02-21 12:16:35 - Failed to enroll certificate for user user-1 (CN=user-1,OU=...) (The certificate is revoked. [0x80092010])
- Certification Authority's "Revoked Certificates" list contains the certificates for a user who was attempting to launch an app.
The Event Viewer's Security log on the RDSH has the event 4685 recorded during the login attempt:
Cause
The certificate of the enrollment user account is revoked.
Resolution
- On the Enrollment Server Agent open MMC via enrollment user account (right-click on MMC > Run as a different user) > File > Add/Remove Snap-in > Certificates > Add > My user account > Finish.
- Open the Personal Certificates Folder, locate the revoked certificate issued via PrlsEnrollmentAgent Template > right-click > Delete.
- Once the certificate deleted, issue a new PrlsEnrollmentAgent certificate to Enrollment Agent user
- Restart RAS Enrollment Agent service.
Was this article helpful?
Tell us how we can improve it.