CCNP MCSE Boot Camp
|
Autoenrollment Functions
This section discusses various functions performed
by the autoenrollment process on Active Directory
domain-joined machines.
Download of Active Directory Certificates and Trust Objects
Autoenrollment automatically downloads and manages
trusted root certificates, cross-certificates, and
NTAuth certificates from Active Directory into the
local machine registry for domain-joined machines.
All users who log on to the machine inherit the
trust and downloaded certificates that are
downloaded and managed by autoenrollment.
Deleting Expired and Revoked Certificates
Autoenrollment deletes expired and revoked
certificates in the userCertificate attribute on the
user object in Active Directory. This feature can be
enabled through user or machine Group Policy to help
ensure that only valid and active certificates are
used for encryption operations.
The exit module on the Windows Server 2003 CA also helps to manage the user account in Active Directory, but only deletes expired certificatesit does not remove revoked certificates due to performance reasons. In general, there is no value in publishing a signing certificate to the user object in Active Directory, except for purposes of record-keeping. Managing User Certificates in the CryptoAPI MY Store
Certificates in the users local MY certificate
store may also be managed through the
autoenrollment process. On a per-template basis,
autoenrollment can be enabled to delete expired and
revoked signature certificates. Encryption
certificates and keys are never automatically
deleted. However, autoenrollment only manages
certificates that correspond to certificate
templates defined in Active Directory that contain
the certificate template extension. This feature is
enabled by setting this policy on the Request
Handling tab in the Properties of a given
certificate template
|
Payless MCSE Boot camp offers Payless MCSE boot camp, MCSE training boot camp, MCSE certification boot camp, MCSE Cisco Boot camp, MCSE Certification training boot camp. MCSE Training certification boot camp, MCSE Boot Training Camp, MCSE boot certification camp, MCSE UK Boot camp, MCSE san Mateo Boot camp, MCSE Japan boot camp, MCSE USA Boot camp, MCSE Europe Boot camp, MCSE guaranteed boot camp.
MCSA : MCSE : MCSE + Security : CCNA : CCNP : Bootcamp : MCSE training : Vibrant MCSE : Vibrant CCNA : Vibrant CCNP : camp : MCITP Boot Camp : CCNA MCITP Boot Camp : CCNA MCSE Boot Camp : MCITP MCSE Boot Camp : MCSE MCITP CCNA Boot Camp : Upgrade MCITP Boot Camp : Upgrade to MCITP CCNA Boot Camp : MCITP MCSE UPGRADE MCITP Boot Camp: : Home : links : Resources : Ref1 : Ref2
|
© Vibrant Worldwide Inc.