MS Certificate Web Enrollment authentication between domains
hi,
i'm trying set certificate enrollment web services give autoenrollment clients. issue clients on separate domain ca. see ces/cep allows 3 options auth (windows, cert, username/password), realistically windows integrated secure enough autoenroll every user.
is there way cep/ces can use windows authentication clients coming domain without having two-way trust? i'm not super experienced these microsoft services.
thanks,
elizabeth.
> there way cep/ces can use windows authentication clients coming domain without having two-way trust?
no, kerberos (integrated auth) requires two-way trust between forests, because 1 of fundamentals in kerberos. how can expose credentials untrusted realm?
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment