Thanks Ken and Ken. I guess I have some reading and work to do. Always
amazed at the depth of knowledge available here. Thanks again for
sharing.

 

From: [email protected]
[mailto:[email protected]] On Behalf Of Brown, Ken F.
Sent: Monday, September 15, 2014 8:31 AM
To: [email protected]
Subject: [NTSysADM] RE: AD 2003 certificates

 

As Ken indicated, certificate autoenrollment of domain joined windows
systems (and users) can be done automatically via active directory - but
does have some requirements.

 

An enterprise CA (certificate of authority) server that a member of the
domain (big hint: DO NOT INSTALL ON A DOMAIN CONTROLLER!) - Microsoft
has a number of articles and documents on how to deploy an enterprise CA
- you may have to dig around for those docs on windows 2003.

 

You'll want to ensure that the 'autoenrollment' option is specified in
your workstations (& servers, if necessary) GPO's - this tells those
systems to check active directory for certificates.

 

Once that is done - you'll configure the appropriate PKI certificate,
determine the scope of auto-enrollment, and deploy it - then watch your
PKI logs to see how quickly the certs are deployed.

 

I did this basic process, albeit with windows 2008 CAs not 2003, and
when I deployed the first company-wide certificate (to all windows
machines)...I started seeing certs get pulled from the CA server within
20 minutes.

 

For your apple clients - I'm not aware they are "AD aware" - and so
you'll have some gyrations to jump thru.  I later setup NDES and SCEP
(PKI infrastructure components) to see if that would ease the deployment
for Mac's and Ipad's - but I don't recall if that ended up being the
method actually used (another internal group was responsible for the
"apple" machines); I know they had to manually copy the certificate
chain down to each machine before it could use the NDES/SCEP that was
setup.

 

Good luck!

 

P.S.  A good book on this, which is what I used, was written by Brian
Komar - PKI and Certificate Security - consider one of the better books
out there...I used the 2008 version - but most of the concepts still
apply for 2003.

 

Some caveats...certificate versions - Win7/2008 and higher can use
version 3 or CNG certificate templates - windows 2003 and lower cannot
(without hotfix for 2003) - ditto for using SHA1 - use SHA2 if you can
(SHA1 has been deprecated by Microsoft...but older OS's can't use SHA2).
Also keep in mind the number of bits (1024, 2048, etc) used in the keys
(most systems can handle 2048 or lower...some applications (like Java)
can't use 2048 or high unless at a specific version).

 

From: [email protected]
[mailto:[email protected]] On Behalf Of Ken Schaefer
Sent: Sunday, September 14, 2014 10:19 PM
To: [email protected]
Subject: [NTSysADM] RE: AD 2003 certificates

 

Warning: Reply address has been set on this email and may not match
displayed sender.

________________________________

Windows 7 machines are capable of auto-enrolling from a Windows Server
2003 Enterprise (i.e. AD integrated) CA. The server doesn't "push" out
the certs - you can use a GPO to have the client auto-enrol the cert
from the issuing CA.

 

Also, are you using a different WLAN management tool to the built-in
Windows client? If using the native Windows WLAN manager then a user
changing their Windows password shouldn't lock-out their account...

 

Cheers

Ken

 

From: [email protected]
[mailto:[email protected]] On Behalf Of Scott Schneider
Sent: Friday, 12 September 2014 11:53 PM
To: [email protected]
Subject: [NTSysADM] AD 2003 certificates

 

We are still stuck on AD 2003. I am attempting to use certificate
authentication for Windows 7 laptops, iPhones and iPads over our
internal WAP's. Radius is setup to our DC's. I am trying to do away with
pre-shared keys or authentication through domain username and password.
Users end up locking themselves out each time they change their windows
password and don't change their wireless credentials. I would like
clients to connect automatically to the WAP's if their device has a
valid cert issued. As far as I know (correct me if I am wrong) Windows
2003 does not natively support pushing certs to Windows 7 clients.

Has anyone successfully used 2003 certs for authentication with Windows
7 laptops? Any other suggestions how it might be accomplished? Care to
share how you did it?

 

Cheers

 

Scott Schneider

Network and Systems Admin

___________________________________
inscape smart workspaces

 

T 905 952 4001
www.inscapesolutions.com <http://www.inscapesolutions.com/> 

 


Reply via email to