From 389 Directory Server
[edit]
Download AEP
Download pre-built binaries of AEP here: [1].
[edit]
Installation/Configuration
Follow these steps to perform the auto enrollment proxy installation and configuration.
- Add Agent Cert:
- Export CA agent certificate into a pkcs12 file and copy that to this windows machine.
- run MMC
- open Certificates - Personal
- open certificates.
- Right click and select import to Import CA agent certificate.
- Next, add the CA's certificate into your domain's group policy:
- Use IE and connect to the CA's agent page. No errors/warning should be displayed. If they appear, make sure they don't appear the next time.
- Go the CA's End-entity port, Retrieval, Import CA Certificate Chain, download CA Certificate Chain in binary form. Save it to your desktop with name 'cacert.cer'.
- run MMC ,
- Goto Active Directory Users and Computers, Right-click on '<DOMAIN>' in the left-hand panel/tree. Select Properties. Select Group Policy tab, Select Default Domain policy, Press Edit.
- Open Computer Configuration->Windows Settings->Security Settings->Public Key Policies->Trusted Root Certification Authorities Right click in the right panel, Select 'Import...'. Open the 'cacert.cer' file you saved earlier.
- AEP Installation:
- Download the AEP executable.
- Double-Click to install it.
- AEP Configuration:
- Configure CA cert
- Populate AD
- Configure CA information ( host / port )
- Configure Logging level.
- Apply.
- DCOM - Configuration:
- open mmc - goto component services
- goto computers -> My Computer -> DCOM Config -> Red Hat Auto enrollment Proxy
- Right click on properties
- Security
- Launch and activation - Customize - make sure administrator is selected.
- Access - Customize it and make sure administrator is selected.
- Identity
- Enter administrator used name and password.
