Issuing Client/computer Certificates which are not part of the domain


hi ,

- have several linux clients contact server (which linux web server) , plan ensure server authenticates every client using client certificate used .none of these machines belong ad domain of enterprise ca .they belong ldap stand alone .

my answer problem have separate sub ca (certified existing enterprise ca ) , feasible  have sub ca belonging domain(ldap domain) altogether ?

or should have root ca ldap domain?

- how issue certificates these clients if they're part of domain ? enabled computer certificate template on enterprise ca dont see on web enrollment interface used requesting   certificates ( see efs , user template there) .

pl advise

thanks

shaun

hi shaun,

is need?

enabling cep , ces enrolling non-domain joined computers certificates

http://blogs.technet.com/b/askds/archive/2010/05/25/enabling-cep-and-ces-for-enrolling-non-domain-joined-computers-for-certificates.aspx

niko



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS