Click here to get back home

Enterprise Ca authority anonymous access

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Enterprise Ca authority anonymous access Nelson 01-16-2007
Posted by Nelson on January 16, 2007, 4:07 pm
Please log in for more thread options
Hi, im trying to enable the access to users to require a certificate in my
enterprise authority. I want that they log as anonymous users. When I enable
the anonymous option access the users cannot login to request the page, in
fact the page receive an error indicating that no certificate templates are
availables with the logon policies that I'm (the user) is using. So, does
anybody if its possible to change the settings to enable anonymous access to
obtain the certificates? What I'm doing is trying to enable users to log in
my wireless using certificates.So, to receive the certificates they dont
belong to any domain. Any clue? I'll appreciatte your help. I've read the
last two days in microsoft and google what it says but I couldn't find any
that helps me.

Thanks,


Posted by Brian Komar [MVP] on January 16, 2007, 9:18 pm
Please log in for more thread options
Nelson@discussions.microsoft.com says...
> Hi, im trying to enable the access to users to require a certificate in my
> enterprise authority. I want that they log as anonymous users. When I enable
> the anonymous option access the users cannot login to request the page, in
> fact the page receive an error indicating that no certificate templates are
> availables with the logon policies that I'm (the user) is using. So, does
> anybody if its possible to change the settings to enable anonymous access to
> obtain the certificates? What I'm doing is trying to enable users to log in
> my wireless using certificates.So, to receive the certificates they dont
> belong to any domain. Any clue? I'll appreciatte your help. I've read the
> last two days in microsoft and google what it says but I couldn't find any
> that helps me.
>
> Thanks,
>
>
Cannot be done with an enterprise CA. Enterprise CA's are all based on identity
which
requires the user to authenticate with the server.

Use a standalone CA in your hierarchy and have the user's provide their subject
and any
necessary OIDs. Ultimately, no access is provided because anonymous users would
not have
access to any certificate templates issued by the enterprise CA.

Brian

Similar ThreadsPosted
Computer Account Changed, by NT AUTHORITY\ANONYMOUS LOGON?! July 3, 2006, 1:48 pm
Enterprise Root Certification Authority not trusted February 16, 2006, 2:07 pm
Migrate Enterprise root authority CA to stand-alone root CA December 13, 2005, 7:57 am
Anonymous folder access December 13, 2006, 9:14 pm
Anonymous Access to Shared Folder November 5, 2007, 1:13 pm
Outlook Compatibility issue with Disabling Anonymous Access September 13, 2007, 2:22 pm
Shares, Named Pipes, and Registry for Anonymous Remote Access February 23, 2007, 2:24 am
LDAP allows anonymous binds September 8, 2005, 9:01 am
Anonymous login to share December 18, 2007, 9:00 am
File Sharing users logon as only Anonymous February 7, 2006, 4:24 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap