Restoring Certificate Services database and enabling NDES
i’d know if our certificate server, has network device enrolment service (ndes) role enabled, needs migrated or restored new hardware. specifically, i’m wondering following 2 certificates issued server during install of ndes:
· exchange enrollment agent (offline request) (enrollmentagentoffline)
· cep encryption (cepencryption)
if install certificate services (using backup of ca key), web enrollment, ndes, , restore certificate database & registry key, wont newly issued certificates ndes (mentioned above) overwritten part of database restore? will cause problem when trying use ndes?
would make more sense install certificate services (using backup of ca key), web enrollment, restore certificate database & registry key, , install ndes? if going route, should original certificates (generated during install of ndes) revoked or deleted first?
background: we’re 2003 native mode domain (single forest, single domain) , we’re installing certificate services on 2 2008 r2 enterprise (domain member) servers. we have root , subordinate (issuing) server. we’re enabling credential roaming our users, largely using xp.
any comments or suggestions welcome...
the second option make more sense. client keys created on client - authorize ndes http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs-en-us.aspx
when setup new ndes server, don't need old ndes keys, should register devices new ndes server.
you realize credential roaming can increase size of active directory database, right? sure review following blog article
http://blogs.technet.com/b/askds/archive/2009/12/18/troubleshooting-credential-roaming.aspx
Windows Server > Security
Comments
Post a Comment