Re: Problem with WIndows 2003 Certificate Services: Computers install certificates from root domain instead of child domain
From: David Cross [MS] (dcross_at_online.microsoft.com)
Date: 11/07/03
- Previous message: S. Pidgorny
: "Re: Kerberos and windows 98" - In reply to: Trond Hindenes: "Problem with WIndows 2003 Certificate Services: Computers install certificates from root domain instead of child domain"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 7 Nov 2003 05:25:07 -0800
yes,
1. make sure you set the ACL on the template specific to the domain
computers you wish to use that template. then set that template to only be
used by a specific CA. note you may have to create multiple templates from
the "computer" template to achieve the result you want
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/deploy/confeat/ws03crtm.asp
-- David B. Cross [MS] -- This posting is provided "AS IS" with no warranties, and confers no rights. http://support.microsoft.com "Trond Hindenes" <trond@hindenes.com> wrote in message news:c175a21a.0311070229.5bdfa9a@posting.google.com... > hello, > We have an Active Directory-based domain structure, domain.com. root > domain has no users, only a few servers. Enterprise root CA is > installed here. I have a child domain for my country (no.domain.com), > which has a Subordinate Enterprise CA installed. THrough GPOs I have > enabled auto-enrollment of Certificates for the Computer accounts in > my domain. However, some of my computers enroll against the root > domain CA instead of my CA. I have looked at the Security tab but that > does only seem to control user enrollments, not computer enrollments. > > Doeas anybody know how to "lock" my computers only to use my local CA > for enrolling? > > best regards, > Trond Hindenes > Consultant > Norway
- Previous message: S. Pidgorny
: "Re: Kerberos and windows 98" - In reply to: Trond Hindenes: "Problem with WIndows 2003 Certificate Services: Computers install certificates from root domain instead of child domain"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
Loading