Restoring Certificate Services database and enabling NDES


i’d know if our certificate server, has network device enrolment service (ndes) role enabled, needs migrated or restored new hardware.  specifically, i’m wondering following 2 certificates issued server during install of ndes:

·         exchange enrollment agent (offline request) (enrollmentagentoffline)

·         cep encryption (cepencryption)

if install certificate services (using backup of ca key), web enrollment, ndes, , restore certificate database & registry key, wont newly issued certificates ndes (mentioned above) overwritten part of database restore?  will cause problem when trying use ndes?

would make more sense install certificate services (using backup of ca key), web enrollment, restore certificate database & registry key, , install ndes?  if going route, should original certificates (generated during install of ndes) revoked or deleted first?

 

background: we’re 2003 native mode domain (single forest, single domain) , we’re installing certificate services on 2 2008 r2 enterprise (domain member) servers.  we have root , subordinate (issuing) server.  we’re enabling credential roaming our users, largely using xp.

 

any comments or suggestions welcome...

the second option make more sense. client keys created on client - authorize ndes http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs-en-us.aspx

when setup new ndes server, don't need old ndes keys, should register devices new ndes server.

you realize credential roaming can increase size of active directory database, right? sure review following blog article

http://blogs.technet.com/b/askds/archive/2009/12/18/troubleshooting-credential-roaming.aspx



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file