creating PKI certificates without using a FQDN in the Name field



Hi all;
I'm hoping someone can shed some enlightenment. I'm configuring SCOM for a
customer and we're trying to monitor machines in a DMZ that are not part of a
domain. In fact although they are in workgroups, there are no workgroup
servers. The servers and PCs that are needing monitoring are all standalone.

We've stood up a standalone root CA, and created certificates for the SCOM
servers, imported them to both the Local Computer store and used
MOMCertImport.exe to use them with SCOM. However, all the documentation I've
seen so far says that to create the certificate for the non-domain machines,
the cert requires a FQDN. How can you use and FQDN for a machine that is not
a member of a domain?

We created a certificate with just the computer name in the Name field, but
seem to have no joy here. To forestall responses about using a Gateway
server, the customer is adamantly opposed to this. (No $$ for the hardware)

So, can anyone help out? (I posted this in the Ops Manager forum as well).
TIA!
.



Relevant Pages

  • Re: [help] 1 cpu to rule them all
    ... >> configuration and maintenance in one place is a lot more economical than ... it isn't the price of the hardware that makes it ... > You can make things easier by having lots of machines that are virtually ... > directories) on servers. ...
    (comp.os.linux.hardware)
  • Re: Creating and AD domain
    ... > None of these machines are reachable from the internet, ... > access the internet, using existing DHCP and DNS servers. ... > As of now, I've got a domain created, the domain controller is up and has ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to access I/O port directly in VC6.0?
    ... As soon as you have standalone machines, ... Their "security" as far as servers was a joke; ... discovered the internal wireless network was completely unencrypted. ...
    (microsoft.public.vc.mfc)
  • Re: Web Services DNS Round Robin
    ... w/ a LB machine inbetwen holding the single IP w/ several machines behind ... or later, as a DNS server. ... Suppose you have 50 identical www.heaven.af.mil web servers running on IP ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Groklaws "Bias" and the SCO DDoS Attack
    ... My machines will fall over before the downstream pipe fills up. ... LAN - again providing you have incoming links fast enough to make a ... You can put your web servers in the dmz and still not ...
    (comp.unix.sco.misc)