Certificate Autoenrollment Cross Domain?
i'm looking build couple of windows 2008 r2 enterprise subordinate issuing ca's within existing pki. ad ds environment multi-domain single forest.
the new ca's issuing sccm client certificates begin with, want them issue these certs multiple domains in forest using autoenrollment.
what wanted confirm if deploy ca's 1 domain, provided have set read, enroll , autoenroll permissions on template domain computers built-in group in other domains, computers in other domains automatically obtain certificate? autoenrollment enabled in gpo domains.
my understanding work, second opinion never bad thing :)
thanks time , can give me.
mcts 70-640 | prince2 practitioner| itil foundation v3 | http://cb-net.co.uk
enterprise ca forest-wide service, allows deploy single ca server domains in forest. need correctly assign permissions on certificate templates — use global and/or unversal groups permissions assignment.
my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki
Windows Server > Security
Comments
Post a Comment