Click here to get back home

using web enrollment for servers etc.

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
using web enrollment for servers etc. Kristin Griffin 02-11-2008
Posted by Kristin Griffin on February 11, 2008, 2:44 pm
Please log in for more thread options
Can the web enrollment feature be used to enroll for only user certificates?
It looks like you can get a server certificate as the "type" drop down box
lists: Server Authentication Certificate.

Can anyone define the limitations of the Web Enrollment feature as pertains
to what inds of certificates you can actaully request and get successfully?

Thanks!

Kristin



Posted by Brian Komar on February 11, 2008, 10:39 pm
Please log in for more thread options
The request is always done in the security context of the user, so you
cannot request typical machine certificates from the Web enrollment pages.
The only type that you can request are ones where the user supplies the
subject in the request.
Brian

> Can the web enrollment feature be used to enroll for only user
> certificates? It looks like you can get a server certificate as the "type"
> drop down box lists: Server Authentication Certificate.
>
> Can anyone define the limitations of the Web Enrollment feature as
> pertains to what inds of certificates you can actaully request and get
> successfully?
>
> Thanks!
>
> Kristin
>


Posted by Kristin Griffin on February 13, 2008, 5:16 pm
Please log in for more thread options
Brian,

I kept messing with it, and I think it is actually working all right. But
the installation telling me that it sucessfully installed a certificate when
it really does not , threw me. It looks like it is only installing
certificates that it can place in the user store. I requested an IPSEC
certificate, which the web enrollment let me do, and I could not get the web
site to actually place this in any store folder. I could do it manually,
but when it came to actually using that certificate, it would not work.
Most likely because the subject needed to be a computer name, and since I
enrolled it using the website, the subject name was a user name instead. So
then why is the IPSEC option even available?

Here is my latest question then.

What exactly can I DO with each of the certificate choices i get under the
advanced option of web enrollment? Lets say I am logged in as "SomeUser".
The choices of certificates are:

Client Authentication
Email Protection - I get this one.
Server Authentication - isnt this a machine cert? so why would I have this
option when my subject would not be a server name?
Code Signing - can this be successfully gotten via web enrollment?
Time Stamp - what is this cert for? again, can it be requested successfully
via web enrollment?
IPSec - this didnt work for a computer (naturally), so is there a purpose I
CAN use it for if I get it via web enrollment with the sunject being a
username, not a computer name?
OtTher -

Many thanks,

Kristin



> The request is always done in the security context of the user, so you
> cannot request typical machine certificates from the Web enrollment pages.
> The only type that you can request are ones where the user supplies the
> subject in the request.
> Brian
>
>> Can the web enrollment feature be used to enroll for only user
>> certificates? It looks like you can get a server certificate as the
>> "type" drop down box lists: Server Authentication Certificate.
>>
>> Can anyone define the limitations of the Web Enrollment feature as
>> pertains to what inds of certificates you can actaully request and get
>> successfully?
>>
>> Thanks!
>>
>> Kristin
>>
>



Similar ThreadsPosted
Re-enrollment of Certificate on Win 2000 June 27, 2005, 3:26 pm
Web Certificate Enrollment problem March 14, 2006, 3:06 am
IAS and RAS server certificate enrollment May 16, 2008, 2:13 pm
Automatic Certificate Enrollment Problems April 5, 2006, 11:45 am
Auto-enrollment setting at different OU levels June 19, 2007, 4:59 pm
CA Services enrollment agent and templates January 10, 2008, 11:02 am
Smart card enrollment issues April 29, 2008, 8:23 pm
Auto cert enrollment without an Enterprise Server June 19, 2006, 2:45 pm
Certificate Enrollment w Firefox and Custom Template February 21, 2007, 8:03 pm
W2K3 SP2 web enrollment w/922706 and Vista client December 5, 2007, 6:24 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap