Re: Autoenrollment - What Does it Do!?

Tech-Archive recommends: Fix windows errors by optimizing your registry



When you install certificate services somewhere in your forest, a DC
template becomes available. DCs will auto-enrol this if they're not running
SP1. If they're running SP1 you must add them to the CERTSVC... group
before they will auto-enrol.

The certificate allows the DCs to perform LDAPS, which is LDAP over SSL. So
its basically an SSL cert.

You are now able to perform simple binds over a secure channel if you use
the explicit host name. Serverless bind won't work due to a hostname and
cert mismatch.


Does it enable encrypted communication to the other DC?

No. You'll need to use IPSec for that. When you do, you can choose to use
either Kerberos or Certificates. Certificates is better; we've had some
issues with Kerberos.


Is the replication data encrypted for transfer?

It is anyway. It's done via secure RPC. If that isn't enough for you, you
have to use IPSec.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net



.



Relevant Pages

  • Re: several annoying error message in all the domain controllers
    ... This looks like a problem with the auto enrollment of the DCs with your ... > Our Windows 2003 Native domain controllers are getting several ANNOYING ... Automatic certificate enrollment for local system failed to ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD PKI question
    ... my problem is not to generate the new CRL... ... certificate is revoked between 2 downloads. ... This certificate was issued by Microsoft Certificate ... So I assume that the DCs will not download the new CRL file more than ...
    (microsoft.public.windows.server.networking)
  • Event-ID:20 KDC certificate was once valid, but now is invalid
    ... bekomme auf meinen beiden 2003 DCs immer wieder folgende ... "The currently selected KDC certificate was once valid, ... The DCs should then ... so dass die DCs auch kein neues Zertifikat bekommen können. ...
    (microsoft.public.de.german.windows.server.active_directory)
  • Re: LDAP over Secure Sockets Layer (SSL) will be unavailable at this t
    ... Unfortunately I'm not a WinCA guy at all (we use external certs for our DCs) and I'm not an RODC guy either so I don't know any of the particulars regarding how this is supposed to work. ... "the permissions on the certificate template do not allow for this type of ... Running at server 2003 operational level. ...
    (microsoft.public.windows.server.active_directory)
  • Event-ID:20 KDC certificate was once valid, but now is invalid
    ... bekomme auf meinen beiden 2003 DCs immer wieder folgende ... "The currently selected KDC certificate was once valid, ... The DCs should then ... so dass die DCs auch kein neues Zertifikat bekommen können. ...
    (microsoft.public.de.german.windows.server.active_directory)