Re: What to do with certificates when profile is deleted/recreated?

From: David Cross [MS] (dcross_at_online.microsoft.com)
Date: 12/09/04


Date: Thu, 9 Dec 2004 05:25:27 -0800

Understood and we are working on alternate solutions.

-- 
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
Top Whitepapers:
Auto-enrollment whitepaper: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx
Best Practices for implementing Windows Server 2003 PKI: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx
Troubleshooting Certificate Status and Revocation whitepaper: 
http://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx
Windows Server 2003 web enrollment and troubleshooting guide: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
Windows Server 2003 web enrollment and troubleshooting guide: 
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
"Stephen Woolhead" <stephen@perfectphase.com> wrote in message 
news:eCclCWS3EHA.2608@TK2MSFTNGP10.phx.gbl...
> Just like to add that I have the same problem.  I would like auto 
> enrolment to not only check if a certificate for a template already exists 
> in AD, but to copy it locally if it does.  This seems such an obvious 
> thing to me I can't under stand why it was not implemented, or have I 
> missed something?
>
> We do not have smartcards or roaming profiles which seems to leave us with 
> manually importing certificates via the MMC or issuing duplicates.
>
> Stephen
>
> "David Cross [MS]" <dcross@online.microsoft.com> wrote in message 
> news:OpqTIni0EHA.3704@tk2msftngp13.phx.gbl...
>> You essentially have two options today:
>>
>> 1.  roaming user profiles
>> 2.  smartcards
>>
>> We understand that you are looking for other options and are working hard 
>> to provide additional options in the future.
>>
>> -- 
>> David B. Cross [MS]
>> --
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>>
>> Top Whitepapers:
>>
>> Auto-enrollment whitepaper: 
>> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx
>> Best Practices for implementing Windows Server 2003 PKI: 
>> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx
>> Troubleshooting Certificate Status and Revocation whitepaper: 
>> http://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx
>> Windows Server 2003 web enrollment and troubleshooting guide: 
>> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
>> Windows Server 2003 web enrollment and troubleshooting guide: 
>> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
>>
>> "Remco de Groot" <me@Xrdegroot.net> wrote in message 
>> news:urvwbgb0EHA.1924@TK2MSFTNGP10.phx.gbl...
>>>I have an environment with Win2K3 and XP. I have it configured for
>>> auto-enrollment which works fine. But:
>>> It often happens that a user uses a different machine. Since roaming
>>> profiles will not be implemented for some time, a new profile for the 
>>> user.
>>> This new profile does not contain the earlier enrolled certificate.
>>> How should I deal with this situation so the user gets his certificate
>>> again. As said, roaming profiles are not an option (yet) further more I 
>>> want
>>> to minimize the user interaction as much as possible.
>>>
>>> Thanx for any input on this.
>>>
>>> Remco
>>>
>>>
>>>
>>>
>>>
>>
>>
>
> 


Relevant Pages

  • Re: Auto-Enrollment of Certificates
    ... Best Practices for implementing Windows Server 2003 PKI: ... Troubleshooting Certificate Status and Revocation whitepaper: ... Windows Server 2003 web enrollment and troubleshooting guide: ...
    (microsoft.public.platformsdk.security)
  • Re: Isolation of the Root CA
    ... Windows Server 2003 web enrollment and troubleshooting guide: ... Best Practices for implementing Windows Server 2003 PKI: ... Troubleshooting Certificate Status and Revocation whitepaper: ... >>> standalone root CA and use it to issue a certificate for an Enterprise ...
    (microsoft.public.win2000.security)
  • Re: Exporting/importing Certificate+private key from remote machin
    ... Best Practices for implementing Windows Server 2003 PKI: ... Troubleshooting Certificate Status and Revocation whitepaper: ... Windows Server 2003 web enrollment and troubleshooting guide: ... > I am running the program as 'Administrator' of remote machine from which I> am trying to copy certificate and private key. ...
    (microsoft.public.platformsdk.security)
  • Re: Auto-Enrollment of Certificates
    ... I am trying to add Certificate Template from Add Standalone Snap-In, ... > Best Practices for implementing Windows Server 2003 PKI: ... > Windows Server 2003 web enrollment and troubleshooting guide: ...
    (microsoft.public.platformsdk.security)
  • Re: decrypting a file question
    ... I seem to have all profiles. ... > profile of the user account that encrypted the file and the Recovery Agent ... The EFS or Recovery Agent ... > certificate needs to show that "you have the private key that corresponds ...
    (microsoft.public.win2000.security)

Loading