Chapter 4. Requesting, Enrolling, and Managing Certificates
96
• Has a trusted CA that is listed in the
CN=Certification Authorities
subtree.
• The last CA in the trust chain must be a self-signed root CA.
4.6.1.2. Planning the Auto Enrollment Configuration
It only requires a single Auto Enrollment Proxy for an entire domain, but it depends on the domain
configuration where and what machine the Auto Enrollment Proxy should be installed on. The proxy
has to be able to authenticate the requester against information in the domain, so the requester must
be in the same forest as the proxy.
Additionally, for security, the proxy should be run on a dedicated machine in a secure environment with
access limited to trusted administrators.
The simplest configuration is to install the proxy as the same machine as the domain controller. This
limits the field of the proxy to that single domain.
Figure 4.3. Having the Proxy on the Domain Controller
Because of traffic or security, it may be better to install the proxy on a dedicated machine within the
domain, but not a domain controller. Depending on the domain configuration, this can also limit the
proxy to entities within the single domain.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...