MS Certificate Web Enrollment authentication between domains


hi,

i'm trying set certificate enrollment web services give autoenrollment clients. issue clients on separate domain ca. see ces/cep allows 3 options auth (windows, cert, username/password), realistically windows integrated secure enough autoenroll every user.

is there way cep/ces can use windows authentication clients coming domain without having two-way trust? i'm not super experienced these microsoft services.

thanks,

elizabeth.

> there way cep/ces can use windows authentication clients coming domain without having two-way trust?

no, kerberos (integrated auth) requires two-way trust between forests, because 1 of fundamentals in kerberos. how can expose credentials untrusted realm?


vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file