Can you setup a Proxy (Registration Agent) to act on behalf of Auto Enrollment rather than going direct to the CA
hello all
can please following question.
the security department work restrict far possible access systems (as might expect).
when comes requesting , receiving certificates ca, wrote powershell script (a shout out vadims here invaluable help) interface between ca, , sql database , a custom web frontend. request certs (e.g. web server, code signing etc.) via web frontend , once approved line manager (again via web frontend) cert created , emailed to user. plus several aspects of the issued cert serial number, expiry date, template name, where cert installed etc. added sql record can reporting down line certs in our estate , automatically email user when cert coming u renewal etc. (we use front end fo revocation requests)
now thing security team want enforce/force users go via system certs (to ensure the sql database reflect true picture). want auto enrolment of user , computer certificates (for cisco ise 802.1x lan/wifi access policy engine) , therefore need allow dcom/rcp cas (as brian explained) auto enrolment to work.
but allow dcom/rpc to ca from any computer on domain the security team concerned user little bit of knowledge use tools certreg , certutil etc request and receive certs manually thereby passing the above system (i have set acl on web server template etc. allow ad account executes script the rights to read, enrol certs based on template/s). however for templates where the user (say the authenticated users group) has read , enrol rights (for example user certificates auto enrolment) the security team concerned user request them manually , install them manually.
sorry long explanation wanted give background
so question is auto enrolment can requests go via proxy (ra) certs ca , thereby need dcom/rpc handful of ras (say via load balanced vip) rather opening rpc/dcom whole network?
but again giving above scenario user still cert manually requesting 1 via proxy or can proxy configured accept auto enrolment requests?
thanks all
ernie
if understand case correctly, configured requirement of 2 signatures in request (in issuance policies tab) , registration authority adds signature incoming request. correct in assumptions?
if yes, can force users use ra renewal requests. in issuance policies tab, there radiobutton group "criteria reenrollment" 2 options: 1) valid existing certificate, 2) same criteria enrollment. need select option 2 (same criteria enrollment). in case, users won't able renew certificates without accessing ra , getting additional signature.
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki.codeplex.com
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment