IPSec NAP with a Enterprise Subordinate CA


the step step guide instructs me use stand alone ca complete lab, i've done , success great greg.

now need enterprise subordinate ca.

i've done following modifications

at hra (same box nps), configure "use enterprise certification authority"

and chose available template (systemhealthauthentication)

then test results, it's quite weird.

the hra did request certificate, it's name "npsservername.mydomain.com", , installed on clients (both domain , non domain clients)

it suppose "clientcomputer$.mydomain.com" right?

what's reason, please help, thank much

mcse mcitp:ea ccnp

hi andrew,

we've exchanged emails on issue already. think that setting certificate template properties "supply in request" on subject name tab fixed problem.

you had interesting results @ first caused certificate "unauthenticated system health authentication" i've seen happen couple other times. issue resolved after 10 minutes. going to investigate why happens.

you mentioned setting template "supply in request" affects autoenrollment. check this.

-greg


Windows Server  >  Network Access Protection



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS