Can I use Win2003 CA to sign cert of non-domain servers?
i need generate certificates internal servers. of servers not , never be on domain. can use win2003 ca server sign certificates servers not on domain?
hi,
thank post.
yes, enterprise ca can issue certificate workgroup user or workgroup computer. can request certificate through web enrollment page or using utility certreq.
certreq.exe syntax
http://technet.microsoft.com/en-us/library/cc736326.aspx
ad cs: web enrollment
http://technet.microsoft.com/en-us/library/cc732517.aspx
in addition, please remember that:
1. workgroup user (or computer) must trust ca.
2. url locations of aia , cdp accessible.
if there unclear, please feel free let me know.
Windows Server > Security
Comments
Post a Comment