From 389 Directory Server
The Auto Enrollment Proxy (AEP) for Windows allows users and computers in a Microsoft Windows® domain to automatically enroll for certificates issued from Red Hat Certificate System.
Designed to integrate seamlessly with your existing Windows infrastructure, the AEP module minimizes the amount of administration:
- Users and computers registered in a Windows domain can automatically discover the location of the proxy on their network
- Computers in a domain can automatically compose a certificate request, and submit it to a Red Hat Certificate System CA via the proxy
- The Kerberos authentication mechanism built into Windows authenticates these certificate requests
- When the CA issue a certificate, it is automatically installed into the requesting application
This solution can issue certificates for domain controllers, web servers, computers, and users.
Setting up the Auto Enrollment Proxy for Windows requires just two steps:
- Install the proxy on one machine in your domain
- Configure it to connect and authenticate to a Red Hat Certificate System CA
Once installed, all domain members may then utilize the Windows auto enrollment features to enroll for certificates.
[edit]
Feature List
- Installer
- Installing the proxy on atleast Win 2003 ( base and SP1 ), Win 2000 AS ( SP4 )
- Un-Installer - to clean up registry settings etc.
- Configuration UI
- Ability to configure CA Certs
- Ability to configure CA connection info
- Populate Active Directory with AEP settings
- Ability to add/remove CA information.
- show version information
- Logging
- Log messages to Event Viewer.
- Different levels to see different types of messages ( Request Processing, Cert Issuance ... )
- Core Operations
- Domain Controller Certificate Enrollment.
- IIS - Web Server Certificate Enrollment
- Computer - cert enrollments [TBD]
- IPSEC - Cert Enrollment [ TBD ]
- Run as a Service ( providing ability to stop , start the service - Starts automatically during boot up )
- Support for Failover
- Interop:
- Provide support for Red Hat Certificate System versions - 7.3, 7.2, 7.1 , 6.1
