Certificate Autoenrollment Cross Domain?


i'm looking build couple of windows 2008 r2 enterprise subordinate issuing ca's within existing pki. ad ds environment multi-domain single forest.

the new ca's issuing sccm client certificates begin with, want them issue these certs multiple domains in forest using autoenrollment.

what wanted confirm if deploy ca's 1 domain, provided have set read, enroll , autoenroll permissions on template domain computers built-in group in other domains, computers in other domains automatically obtain certificate? autoenrollment enabled in gpo domains.

my understanding work, second opinion never bad thing :)

thanks time , can give me.


mcts 70-640 | prince2 practitioner| itil foundation v3 | http://cb-net.co.uk

enterprise ca forest-wide service, allows deploy single ca server domains in forest. need correctly assign permissions on certificate templates — use global and/or unversal groups permissions assignment.


my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki


Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file