Can I use Win2003 CA to sign cert of non-domain servers?


i need generate certificates internal servers.  of servers not , never be on domain.  can use win2003 ca server sign certificates servers not on domain?

hi,

thank post.

yes, enterprise ca can issue certificate workgroup user or workgroup computer. can request certificate through web enrollment page or using utility certreq.

 certreq.exe syntax
http://technet.microsoft.com/en-us/library/cc736326.aspx

ad cs: web enrollment
http://technet.microsoft.com/en-us/library/cc732517.aspx

in addition, please remember that:

1. workgroup user (or computer) must trust ca.

2. url locations of aia , cdp accessible. 

if there unclear, please feel free let me know.



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS