CA enrollment issues.

CA enrollment issues.

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
CA enrollment issues. Mike Cave 06-22-2005
Posted by =?Utf-8?B?TWlrZSBDYXZl?= on June 22, 2005, 10:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm implementing the 802.11 wireless using Windows. My network consist of 2
forest and one child. In domain A I created a Enterprise CA "its a windows
2003 standard server" and started auto enrolling certificate to computers in
domain A and everything is fine. In the other two domains certifiactes arent
getting issued. Is CA only domain specific? Can I have one CA to be
responsible for the enterprise?I made the same group policy change in domain
B and C as I did A. Thoughts?

-Michael

Posted by Mark Gamache on June 22, 2005, 12:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
First, your description says you have 2 forests. Autoenrollment can not
work cross forest, to my knowledge. One might be able to make that happen
with a two way trust and the right AD duct tape and super glue.

Assuming that you meant there was a single forest with a total of 3 domains,
make sure that the templates have had their permissions changed to allow
members of the other domain to enroll and auto enroll.

Cheers,

--
Mark Gamache
Certified Security Solutions
http://www.css-security.com



> I'm implementing the 802.11 wireless using Windows. My network consist of
> 2
> forest and one child. In domain A I created a Enterprise CA "its a windows
> 2003 standard server" and started auto enrolling certificate to computers
> in
> domain A and everything is fine. In the other two domains certifiactes
> arent
> getting issued. Is CA only domain specific? Can I have one CA to be
> responsible for the enterprise?I made the same group policy change in
> domain
> B and C as I did A. Thoughts?
>
> -Michael



Posted by Steven L Umbach on June 23, 2005, 12:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Keep in mind that you are not really using autoenrollment but "automatic
request" for computer certificates. Autoenrollment requires version 2
certificate templates which are only available when you install an
enterprise CA on Enterprise version of Windows 2003 Server. See the link
below on how to allow child domain computers to obtain certificates from a
parent domain CA. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;281271

> I'm implementing the 802.11 wireless using Windows. My network consist of
> 2
> forest and one child. In domain A I created a Enterprise CA "its a windows
> 2003 standard server" and started auto enrolling certificate to computers
> in
> domain A and everything is fine. In the other two domains certifiactes
> arent
> getting issued. Is CA only domain specific? Can I have one CA to be
> responsible for the enterprise?I made the same group policy change in
> domain
> B and C as I did A. Thoughts?
>
> -Michael



Similar ThreadsPosted
Web enrollment, only web server template December 5, 2007, 9:41 am
another port for web enrollment support within CA January 15, 2008, 5:49 am
Error in CLM, Smartcard enrollment April 15, 2008, 7:16 pm
Templates not showing in Web enrollment July 3, 2008, 8:29 am
Web Certificate Enrollment security problem March 15, 2006, 2:57 am
Multiple CAs& user auto enrollment June 12, 2006, 4:39 pm
PKI: choosing an enrollment method advice January 22, 2007, 6:04 pm
Problem with WLAN IAS certificate enrollment May 16, 2008, 11:51 am
Enrollment agent cannot enroll on behalf of a user... July 10, 2006, 4:38 pm
Computer Auto Enrollment for non-windows platforms November 9, 2006, 3:22 pm

The site map in XML format XML site map

Contact Us | Privacy Policy