Re: Issue Certificate to AD Users

From: Dmitrii S. Zakharov [MSFT] (dmitriiz_at_online.microsoft.com)
Date: 04/05/04

  • Next message: Fabien: "Global Access Denied when submitting certificate request"
    Date: Sun, 4 Apr 2004 23:09:12 -0700
    
    

    Hi, Allie,
    x509 certificates are not directly associated with Active Directory. They
    are issued to so called Common Name (CN). However, an AD user, logged into
    windows, can install his certificate to CurrentUser system store. That way
    programs running in his logon session will have access to his certificate
    and will use it for establishing SSL connection.

    In addition, you can use Active Directory to establish explicit mapping of a
    certificate to domain account. (Ask if you need more details on exact
    procedure). In that case such a certificate should be stored at Domain
    Controller.

    -Dmitrii

    "Allie" <moonghost@tom.com> wrote in message
    news:O8Saz#rGEHA.1264@TK2MSFTNGP10.phx.gbl...
    > Hello All,
    > I want to know how could I issuing certs to AD Users.
    > eg.I can issue a cert for testuser@test.com and then testuser could use
    this
    > cert to logon and access the website that needs SSL.
    > what should I do when making Cert Request?
    > allie
    >
    >


  • Next message: Fabien: "Global Access Denied when submitting certificate request"

    Relevant Pages

    • Re: IIS Certificate Mapping password retreival
      ... themselves get stored in AD when you do the AD Mapping. ... Then install Cert Server as a root Enterprise CA ... "Active Directory Mapping" for more details.)" ... when the IIS server receives a certificate ...
      (microsoft.public.inetserver.iis.security)
    • Re: SSLinstall problem
      ... You error message seems to indicate there may already be a Certificate ... Authority but the CA certificate is not published in Active Directory. ... you try to install a CA on a non domain computer make sure you are trying to ... domain computer double check that the domain computer is using ONLY Active ...
      (microsoft.public.windows.server.networking)
    • Re: SSLinstall problem
      ... You error message seems to indicate there may already be a Certificate ... Authority but the CA certificate is not published in Active Directory. ... you try to install a CA on a non domain computer make sure you are trying to ... domain computer double check that the domain computer is using ONLY Active ...
      (microsoft.public.windows.server.security)
    • Re: WLAN Server Certificate for private internal AD Domain
      ... > Does anyone know if that FQDN has to correspond to my Active Directory ... you can also use a Certificate issued by your own ... > on the internet therefore I am unable to prove to verisign that I am ...
      (microsoft.public.internet.radius)
    • [Concepts]: cn and userCertificate vs userPrincipalName
      ... Windows PKI and Active Directory quite well - you go to the Web portal, ... certificate to authenticate, ...
      (microsoft.public.windows.server.security)