Re: Share certificate services between two domains



On 19 sep, 12:26, "Brian Komar" <brian.ko...@xxxxxxxxxxxxxxxxx> wrote:
It comes down to your forest design. If the two domains are in the same
forest, then yes, the enterprise CA can process requests from both domains.
If not, then you need enterprise edition for the cAs in both forests

Thanks.

My goal is allow users to make smart card logon with certificates from
the /local/ CA and an external CA. I know that with a Standalone CA I
can create certificates for users with arbitrary names
(user1@xxxxxxxxxxx, user2@xxxxxxxxxxxxx, etc) and use them to perform
smart card logon, but a Standalone CA cannot create certificates with
the template "Smart card logon" , this certificates are available only
in a Enterprise CA.

¿How can I accomplish this?

Thanks

.



Relevant Pages

  • Re: Active Directory in a huge single forest
    ... > workstations in this forest. ... A migration is planned but not in the near future. ... > I just got asked to provide a 'worst-case' report for our enterprise> active directory. ... that it was MS was recommending for enterprises. ...
    (microsoft.public.win2000.active_directory)
  • Re: 2003/R2 certificate server questions
    ... running OPenSSL to service requests from Linux/samba ... certificates, but I also want to be able to issue random certificates ... Make sure you are running on Enterprise Edition, ... Automatic certs, Key archival and recovery, customizable ...
    (microsoft.public.windows.server.security)
  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... we will need to have trust ... As far as standard versus enterprise, ... If the root CA is compromised your whole PKI ... > your certificates then it would make sense to use your own CA. ...
    (microsoft.public.windows.server.security)
  • Re: client user certificates
    ... in certificates using Windows Server 2003 Enterprise Edition Enterprise CAs ... but it would be nice if there was a way to autoenroll the user. ... We have a Windows Server 2003 domain environment with a Enterprise ...
    (microsoft.public.windows.server.active_directory)
  • RE: CA Client Certificates only expire in one years time
    ... If this was installed as an Enterprise CA this is normal. ... which in v1 templates cannot be modified. ... "For certificates that are issued by Enterprise CAs, the validity period is ...
    (microsoft.public.windows.server.general)