Click here to get back home

PKI User certificate auto-enrollment for XP clients not logging onto domain computer

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
PKI User certificate auto-enrollment for XP clients not logging onto domain computer Enrico 05-18-2007
Get Chitika Premium
Posted by Enrico on May 18, 2007, 11:02 am
Please log in for more thread options
Hello,

I am currently in the process of researching the features of user
certificate autoenrollment for a proof of concept using Outlook Web
Access to an Exchange 2007 environment.

I would like to implement a scenario where a user provisioned with an
exchange email box and address would be able to automatically obtain a
user certificate from the CA by accessing a secure portal or OWA.

1. Given that autoenrollment works via winlogon or Group policy, the
user should be able to obtain the certificate since they are
authenticating to AD with their username/password (as the user is a AD
account object), correct?

2. Does autoenrollment only work when a user logs onto a VPN or a
computer that is physically on the domain of the issuing CA?

Any links to documentation outlining this feature of PKI would be much
appreciated.


Thank you,

Enrico


Posted by Brian Komar on May 19, 2007, 3:56 pm
Please log in for more thread options
Some answers inline.

On 18 May 2007 08:02:35 -0700, Enrico wrote:

> Hello,
>
> I am currently in the process of researching the features of user
> certificate autoenrollment for a proof of concept using Outlook Web
> Access to an Exchange 2007 environment.
>
> I would like to implement a scenario where a user provisioned with an
> exchange email box and address would be able to automatically obtain a
> user certificate from the CA by accessing a secure portal or OWA.

They could access the certificate from a secure portal. OWA does not have
any certificate enrollment code included.
>
> 1. Given that autoenrollment works via winlogon or Group policy, the
> user should be able to obtain the certificate since they are
> authenticating to AD with their username/password (as the user is a AD
> account object), correct?

No. The computer must also be a member of the forest. Although the user
account is used, there is no knowledge of an enterprise CA, available
certificate templates, etc.

>
> 2. Does autoenrollment only work when a user logs onto a VPN or a
> computer that is physically on the domain of the issuing CA?
Correct. The user and the computer must be a member of the forest. Even in
a VPN scenario.

>
> Any links to documentation outlining this feature of PKI would be much
> appreciated.

Look for the autoenrollment whitepaper available at www.microsoft.com/pki.
I also cover it in my PKI book.

>
>
> Thank you,
>
> Enrico

Similar ThreadsPosted
Normal user logging onto Win2003 Domain Controller? December 3, 2007, 7:03 am
Autoenrollment problems - Enrollment access is not allowed to this template computer September 1, 2006, 4:02 pm
Certificate autoenrollment and AD publishing July 24, 2008, 9:15 am
domain access control for local user of domain computer? April 3, 2008, 5:14 pm
Microsoft PKI: problem with autoenrollment for domain controllers August 14, 2007, 8:51 am
How to configure Domain access permissions for a user that would vary based on the computer they log into? June 21, 2006, 11:58 am
prevent user from logging on to servers March 31, 2006, 8:22 am
Child domain laptops autoenrolling user certs but not computer certs May 21, 2008, 4:19 pm
How2: User Rights on Domain but Admin Rights on Computer December 20, 2006, 3:40 pm
vista domain clients no longer see USB drives June 9, 2008, 7:05 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap