The System could not log you on. The revocation status of the smart card certificate used for authentication could not be determined

OS: Windows 7, Windows 10

Server OS: Windows 2003, 2008, 2008 R2, 2012, 2012 R2 and Windows Server 2016

Condition: Error message when we use smart to log in on a domain computer.

Cause:  This happens when Certificate Authority (CA) service stopped and CA is unable to publish the CRL (certificate revocation list) and revocation list is expired.

Solution: Log in to CA server using CA admin user.

Click Start à Run à Services.msc and press Enter to open services console.

Check “Active Directory Certificate services”, if the service is stopped, then Right Click à Click on Start.

Wait for some time, CA should publish the new CRL. If you want to force the CRL publication then follow below steps.

Click Start à Run à Control and Press Enter to open Control Panel.

Double Click Administrative tools à Double Click on Certificate Authority.

Right Click on Revoked Certificates à All Tasks à Publish




Now ask the user to restart their client machines so that client machines can receive the renewed CRL from CRL distribution and users can log into their machines using smart cards.

Comments

Popular posts from this blog

The System could not log you on. The revocation status of the smart card certificate used for authentication could not be determined

Unblock gemalto .net smart cards using Gemalto response calculator

How to check who killed process in windows