getting IPSec Certificates for VPN access for non domain members



We have implemented certificate based L2TP/IPSec VPN solutions on different
customer sites based on Enterprise CA's and RRAS, most of them on Windows
2003 standard edition.

- certificates for domain computers are automatically distributed over GPO
and active directory

- certificates for external notebook computers are installed over the
https://servername/certsrv Website when these notebooks are connected to the
internal LAN

We have now virtualized our remote support workstations and need machine
certificates for VPN remote access. Moving our physical virtual server to
the customers is not an option. Have discovered that the private key of an
installed certificate on one of our notebooks is marked as not exportable.
The reaseon for this is probably the original Microsoft IPSec (offline
request) template. Have then successfully duplicated the IPSec (Offline
Request) template, and changed the "export private key" property of the
duplicated template. But this new template can not be enabled in the
certification authority Administration tool, it's not available.

- Is this a limitation of Windows 2003 standard edition?
- Is there a solution to get the certificate requested on
https://server/certsrv into a file for installing the certificate on another
computer?
- Does anyone knows another way to get a customer certificate into the
certificate store of our remote support computer?

Thank you all in advance for any help!
Franz


.



Relevant Pages

  • Re: harddrive DoD datawipe certificate
    ... customer require harddrive DoD datawipe as option. ... we'd like to provide some sort of certificate ... For string certificates you would need a tamper-proof disk wipe ... And a reliable way to tie the certificate to the disk. ...
    (comp.sys.ibm.pc.hardware.storage)
  • getting IPSec Certificates for VPN access for non domain members
    ... We have implemented certificate based L2TP/IPSec VPN solutions on different ... customer sites based on Enterprise CA's and RRAS, ... certificates for domain computers are automatically distributed over GPO ... Request) template, and changed the "export private key" property of the ...
    (microsoft.public.windows.server.security)
  • Re: harddrive DoD datawipe certificate
    ... customer require harddrive DoD datawipe as option. ... we'd like to provide some sort of certificate ... Let me know if anyone know any sort of software or hardware system ...
    (comp.sys.ibm.pc.hardware.storage)
  • Re: WS Security issues
    ... I can't generate the certificates when I install my product? ... > Yes you do have to redistribute the x509 if you choose to use it. ... >> But dont I then have to redistribute a new X509 certificate per customer? ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Code Signing Question?
    ... Recently one of our customers called and complained about the Security Warning dialog that is coming up on their system. ... What happens when the certificate expires and I have to renew it, does it mean that I have to send out a new certificate file to every single customer? ... When the cert expires, you won't be able to sign your .exe's with it anymore. ...
    (microsoft.public.vc.mfc)