RE: Using Subordinate CA's

From: Scotty (Scotty_at_discussions.microsoft.com)
Date: 01/28/05


Date: Fri, 28 Jan 2005 12:07:05 -0800

Wow. That was easy. Can computers be set up to request a certificate
automatically? I read where the GPO can be set up to where the computer
request a certificate for the PC, but what about User Certificates?

"Brian Komar" wrote:

> In article <D9869C23-1A34-4C83-BE99-9EE4E35E3602@microsoft.com>,
> Scotty@discussions.microsoft.com says...
> > Sorry this is a duplicate of the thread above.
> >
> > "Scotty" wrote:
> >
> > > At one of my locations I setup an Enterprise Root CA, then also at the same
> > > location I set up a Enterprise Subordinate CA. When I request a new
> > > certificate through the Snap-in, it request a certificate from my Root CA
> > > instead of my subordinate CA. How can I force the computers to request from
> > > the Subordinate CA?
> >
> Do an advanced request. This allows you to choose which enterprise CA
> for the request submission
>
> Brian
>



Relevant Pages

  • Re: Computer and User Certificates Issues
    ... Enrollment of User Certificates using the custom v2 User Certificate Template ... I can NOT request the custom v2 Computer Cert nor the included v1 no ... Concerning permissions, these are the exact permissions I am using now: ...
    (microsoft.public.security)
  • Re: Cannot request computer certificate.
    ... request a computer certificate for about 9 months. ... and verify that you can get a computer/server certificate from it. ... List of NetBt transports currently bound to the Redir ... DNS Host Name: srvr3.domain.com ...
    (microsoft.public.windows.server.security)
  • RE: SIMple SSL question ??
    ... OK - i would also delete a cert request file lying around. ... But a certificate is a pub key + extra info. ... That said - if someone compromises the server he will also find a way to retrieve the private key. ... traffic between the initial web server and the client. ...
    (microsoft.public.dotnet.security)
  • Re: how can we restrict what certificate WSE will use?
    ... the valid x509 certificate which is used to identify him'. ... X509SecurityTokenManager to verify the request is from a trusted client. ... the problem is that he can not passed the authentication (suppose we ... > decrypte and signature validation process. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Web Certificate Enrollment security problem
    ... Enrollment works only with the NetBIOS Name and not with the FQDN. ... Svyatoslav Pidgorny, MS MVP - Security, MCSE ... access auditing and logging "issue and manage certificate requests" on ... Have seen that there is a component "Certsrv Request" when launching ...
    (microsoft.public.security)