Re: Machine Cert Question - Web Request Question



Inline...
"JSC" <JSC@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:74B7FE85-37D9-49A5-9A21-E1018705D39A@xxxxxxxxxxxxxxxx
We are looking to deploy machine certs in our domain for 802.1x port based
authentication.

My question is what is the difference between the computer cert template and
the workstation cert template? Both say they can be used for
workstation/server authentication. Is the Computer cert a V1 cert and the
Workstation V2? Anybody have any experience setting this up in their
environment that will be willing to share information, I would appreciate it.

They are essentially the same. Both allow autoenrollment but through different mechanisms. Computer (a v1 cert) allows autoenrollment through ACRS. Workstation Authentication deploys through Autoenrollment Settings.

In testing I have both workstation and the computer cert template loaded on
my CA, but I cannot seem to get these certs to show up as available to
request through the certificate web pages. I will need to be able to do this
for machines that are not connected to the domain to get it through
autoenrollment and Apple OS X machines.

Neither is available through the Web pages because Web page requests are done in the security context of the user, and these certificates are requested through the machine's identity. You would have to create a custom certificate template (based on either workstation or computer) that allows the subject to be provided in the request.



.



Relevant Pages

  • Re: Computer and User Certificates Issues
    ... > Enrollment of User Certificates using the custom v2 User Certificate Template ... > request the new custom v2 User Cert that supports auto-enrollment as well as ... > the included version 1 no autoenrollment User Cert manually through the MMC. ... > Custom Computer Cert Security Permissions: ...
    (microsoft.public.security)
  • Re: Pocket PC 2003 - Can access OMA etc, but cannot sync with ActiveSync
    ... I think I originally imported the wrong cert from the workstation. ... of problem on SBS2k and Win2k where Exchange is in the default site and the ... I tried to install the certificate yesterday ...
    (microsoft.public.windows.server.sbs)
  • Re: Certificate Services Question
    ... When I try enrolling in this cert from an XP workstation, ... You can use either template for your ... >> - Sigature for Key Usage ...
    (microsoft.public.win2000.security)
  • Re: Machine Cert Question - Web Request Question
    ... the subject tab to state that the subject is provided in the request. ... Would this be like creating a template with a combination of workstation ... My question is what is the difference between the computer cert ...
    (microsoft.public.windows.server.security)
  • Re: Wireless Radius Clients
    ... It uses the computer cert and the user ... set it as a Radius Client. ... I have a computer cert on the IAS ... Did you create an IAS policy to allow 802.1? ...
    (microsoft.public.windows.server.networking)

Loading