CES/CEP in Intranet with single forest


in scenario ces/cep preferred on certificate request wizard (or alternatives) requesting certificates when in intranet single forest?

i have read article http://social.technet.microsoft.com/wiki/contents/articles/7734.certificate-enrollment-web-services-in-active-directory-certificate-services.aspx#intranet_with_a_single_forest.

in scenario when non domain joined users use perimeter ces certificate renewal (http://social.technet.microsoft.com/wiki/contents/articles/7734.certificate-enrollment-web-services-in-active-directory-certificate-services.aspx#renewal_only_mode) correct request original certificate using other way internal ces/cep?

> in scenario ces/cep preferred on certificate request wizard (or alternatives) requesting certificates when in intranet single forest?

1) cep/ces not replace certificate request wizard.

2) cep/ces in internal domains preferred when want hide ca servers forest members. example, put cas in dedicated vlan limited access (though, ca servers should have full connectivity domain controllers), ces service can contact icertrequest interface on ca server.


my weblog: en-us.sysadmins.lv
powershell pki module: pspki.codeplex.com
powershell cmdlet editor pscmdlethelpeditor.codeplex.com
check out new: ssl certificate verifier
check out new: powershell fciv tool.



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group