Subordinate CAs issuing multiple certificates through auto-enrollment
i have offline root ca; , 2 subordinate cas (one in hq , 1 in dr) both running , active services installed directly on them.
i have configured group policy auto-enroll using these 2 servers; , have configured 2003 certificate template (copy of computer template) client authentication used wireless access.
when apply policy, find computers enrolling mutliple times in "issued certificates" store; in local store see 1 certificate; , have enabled in template feature "do not automatically reenroll if duplicate certificate exists in active directory" some how has not prevented re-enrolling , disaster both sub-cas re-enrolling each computer, computer getting 1 certificate each subordinate ca.
this urgent, ideas helpful
+--+--+--+--+--+--+--+--+--+--+ hany elkady infrastructure consultant +--+--+--+--+--+--+--+--+--+--+
ok, have figured out. searches in future...
- windows xp incompatible windows 2008 r2 gpos , breaks lots of things if gpo created 2008 r2 if forest 2008 or 2003
- windows xp needs hotfix allow enrol 2003/2008 templates (i.e. version 2 & 3) if hotfix not installed, facing above; computer enrolles in 1 subca , not able save certificate because doesn't understand hash algorithim; requests second subca, , same thing happens again. next time user logs in or pulse happen, same process repeated. along subcas have been issuing certificates no problems computer has not been reading them.
- i have not enabled again ad checking or saving, , have wait until deploy hotfix through sccm first before can that; in meantime, have created 2 group policies, 1 allowing windows vista & 7 machines autoenroll normal 2003 certs; , other xp machines allow them pick standard computer certificate.
n.b. looking again, hotfix xp , 2003 machines can found @ kb968730
+--+--+--+--+--+--+--+--+--+--+ hany elkady infrastructure consultant +--+--+--+--+--+--+--+--+--+--+
Windows Server > Security
Comments
Post a Comment