Using Subordinate CA's

G

Guest

At one of my locations I setup an Enterprise Root CA, then also at the same
location I set up a Enterprise Subordinate CA. When I request a new
certificate through the Snap-in, it request a certificate from my Root CA
instead of my subordinate CA. How can I force the computers to request from
the Subordinate CA?
 
G

Guest

Wow. That was easy. Can computers be set up to request a certificate
automatically? I read where the GPO can be set up to where the computer
request a certificate for the PC, but what about User Certificates?
 
B

Brian Komar

Wow. That was easy. Can computers be set up to request a certificate
automatically? I read where the GPO can be set up to where the computer
request a certificate for the PC, but what about User Certificates?

If you are using the Windows Server 2003 enterprise CAs, running on
Windows Server 2003, Enterprise Edition, you can enable autoenrollment
for user through a combination of Version 2 certificate templates and
Group Policy.

The client computers *must* be running Windows XP.

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/plan/auto
enro.asp

Alternatively, I have included a vbs script in my book that allows you
to perform scripted enrollment (automated enrollment) for user
certificates on Windows 2000 clients with CAPICOM loaded.

http://www.microsoft.com/MSPress/books/6745.asp

Brian
R
 
G

Guest

I am running Windows 2000 Server.

Brian Komar said:
If you are using the Windows Server 2003 enterprise CAs, running on
Windows Server 2003, Enterprise Edition, you can enable autoenrollment
for user through a combination of Version 2 certificate templates and
Group Policy.

The client computers *must* be running Windows XP.

http://www.microsoft.com/technet/prodtechnol/windowsserver2003/plan/auto
enro.asp

Alternatively, I have included a vbs script in my book that allows you
to perform scripted enrollment (automated enrollment) for user
certificates on Windows 2000 clients with CAPICOM loaded.

http://www.microsoft.com/MSPress/books/6745.asp

Brian

R
 
B

Brian Komar

I am running Windows 2000 Server.

If you are running Windows 2000 CAs, you can still use my script to
request certificates for user certificates.

Brian
 
S

Shreeniwas Kelkar [MSFT]

You should set up only the Sub CA to issue the templates you want. You can
do this by adding/removing certificate templates from under the certificate
templates node in the MMC CA snapin.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top