performs the installation must be a member of the domain and have sufficient
administration privileges. For example, the user must be a member of the Domain
Admins group.
Make sure the CA that you installed is configured to generate certificates
automatically (this is the default setting) so that Intel SCS can request a certificate
each time it performs a setup of an Intel AMT device. Otherwise, you have to
intervene each time a device is set up.
Warning:
To enable Web enrollment for certificates, install IIS before installing
the CA.
See
“About installing Microsoft IIS”
on page 36.
To install the CA
1
On the computer where you want to install the CA, click the Windows Start
button, and then click Control Panel > Add or Remove Programs >
Add/Remove Windows Components.
2
On the Windows Components Wizard page, check Certificate Services.
A warning is displayed indicating that the computer name or the domain
membership of the computer cannot be changed while it acts as a certificate
server. Click Yes.
3
Click Details. Make sure that both Certificate Services CA and Certificate
Services Web Enrollment Support are checked, and then click OK.
4
Click Next.
5
On the CA Type page, select either Enterprise root CA or Stand-alone root
CA and click Next.
6
On the CA Identifying Information page, type the common name for this
CA.
This is the name by which the CA will be known.
7
Type the distinguished name suffix, if it is not already there.
This is the domain suffix of the host. It is generated automatically in an Active
Directory environment.
8
Click Next.
9
Click Next.
10
If there is a message that requests to stop the IIS, click Yes.
The installation runs to completion.
37
Planning for Out of Band Management Component installation
Installing and configuring CA