I am trying to do a web-enrollment of the ConfigMgr Client, Distribution Point and Web Server certificate on my MP/DP/SUP in the DMZ.
My PKI templates have the proper permissions. I have confirmed this by browsing to https://CAserver.fqdn.com/certsrv The question I have for each of these templates is what options do I select when doing web enrollment: Key Options: Key Usage: Exchange, Signature or both? Additional Options: Request Format: CMC or PKCS10 Does anyone have a blog they can point me to that might talk about setting up the CM/PKI Certs using Web Enrollment? Thanks, Brian

