Re: How to request a COMPUTER certificate using EAP-TLS and w2k3 IAS

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



It is easy if your MS CA is running as standalone, not as enterprise CA.
As I understand, your MS CA is running as enterprise CA. You then need to
tweak the server's pages (HTML/ASP).

Regards,

/Thomas

"Peter Ullrich" <unendlich@xxxxxx> wrote in message
news:79669$43026004$506c39c9$30812@xxxxxxxxxxxxxxxxx
> Hello!
>
> System architecture: WinXP-Clients (WLAN), 3Com/Cisco AP, W2k3 Enterprise
> Server, Enterprise single tier CA running.
>
> Is there a way to request a computer certificate for an WLAN-Client
> computer which is not part of the domain? Optaining an user certificate is
> no problem via web enrolment (servername/certsrv)without being part of the
> domain, but how to get the computer cert?
>
> I also tried to open the certificate snap-in for remote computers and
> choose the WLAN-Client computer (which is registered in AD). But when i
> try to expand the tree I get the error message, that I dont have the
> permission to manage the certificate store for this remote computer (I was
> logged on as administrator)
>
> So how can I get a COMPUTER cert without beiing part of the domain?
>
>
> Would be nice, if anyone has suggestions or something like that :-)
>
> greetings
>
> Peter


.



Relevant Pages

  • RE: Upgrade Standard CA to an Enterprise CA
    ... Do you mean you want to migrate the stand-alone CA to Enterprise CA? ... Back up the certificate database, the CA certificate, and the CA private ... 8.Select Preserve existing certificate database to use the old database. ...
    (microsoft.public.security)
  • Re: Isolation of the Root CA
    ... If you want to put your Enterprise CA behind a firewall, ... practice article on that? ... >> An Enterprise CA can not be an offline CA. ... >> standalone root CA and use it to issue a certificate for an Enterprise CA ...
    (microsoft.public.win2000.security)
  • Re: EFS and Certificate Services
    ... > I created a Enterprise Root CA with a Enterprise Subordinate CA for issuing ... An Enterprise Root CA computer cannot be offline. ... I check the thumbprint of the file and the certificate which matched. ... The best practice is to issue the certificates *before* any encryption ...
    (microsoft.public.win2000.security)
  • Re: W2K3 3-tier CA Implementation
    ... No matter what environment you are in, install a standalone ROOT CA. ... based on the standalone subordinate CA. ... I agree with issuing CAs being enterprise CAs. ... You do not use a certificate tempalte for the ...
    (microsoft.public.security)
  • Re: Subordinate CA
    ... CA servers Enterprise CA setup? ... How was certificate issued to OWA? ... > My company has an Enterprise Root CA in Colorado and many Subordinate CA ...
    (microsoft.public.win2000.security)