You are here
SEC0011 - Windows 2008 CA SCEP Auto-Enrollment Options
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video presents you with various options to implement certificate Auto-Enrollment for network devices using SCEP. By default, a one-time challenge password needs to be generated and used per network device. This can be cumbersome and impractical in case the number of device is large. An alternative is to disable the use of challenge password entirely, but this could post security concern, although is potentially desirable in lab environment. An acceptable solution might be disabling auto-approval and have the CA admin approve certificate requests manually.
Topic includes
- SCEP Auto-Enrollment
- Disabling SCEP challenge password
- Disabling SCEP auto-approval