Extreme Networks Summit WM Technical Reference Manual page 37

Version 5.1
Hide thumbs Also See for Summit WM:
Table of Contents

Advertisement

existing certificate templates, a feature that is only supported for Windows Server 2003, Enterprise
Edition, or Windows Server 2003, Datacenter Edition, enterprise CAs.
Only Windows XP and Windows Server 2003 wireless clients support user certificate autoenrollment.
To configure user certificate enrollment for a Windows Server 2003, Enterprise Edition, or Windows
Server 2003, Datacenter Edition, enterprise CA:
1 Click Start, click Run, type mmc, and then click OK.
2 On the File menu, click Add/Remove Snap-in, and then click Add.
3 Under Snap-in, double-click Certificate Templates, click Close, and then click OK.
4 In the console tree, click Certificate Templates. All of the certificate templates will be displayed in
the details pane.
5 In the details pane, click the User template.
6 On the Action menu, click Duplicate Template.
7 In the Display Name field, type WirelessUser (example name).
8 Make sure that the Publish Certificate in Active Directory check box is selected.
9 Click the Security tab.
10 In the Group or user names field, click Domain Users.
11 In the Permissions for Domain Users list, select the Enroll and Autoenroll permission check boxes
and then click OK.
12 Open the Certification Authority snap-in.
13 In the console tree, open Certification Authority, then the CA name, then Certificate Templates.
14 On the Action menu, point to New, and then click Certificate to Issue.
15 Click WirelessUser (example) and click OK
16 Open the Active Directory Users and Computers snap-in.
17 In the console tree, double-click Active Directory Users and Computers, right-click the domain
system container that contains the wireless user accounts, and then click Properties.
18 On the Group Policy tab, click the appropriate Group Policy object (the default object is Default
Domain Policy), and then click Edit.
19 In the console tree, open User Configuration, then Windows Settings, then Security Settings, then
Public Key Policies.
20 In the details pane, double-click Autoenrollment Settings
21 Click Enroll certificates automatically.
22 Select the Renew expired certificates, update pending certificates, and remove revoked certificates
check box.
23 Select the Update certificates that use certificate templates check box and click OK
Perform steps 17-23 for each domain system container as appropriate.
Best Practices
If you use a Windows Server 2003, Enterprise Edition, or Windows Server 2003, Datacenter Edition,
enterprise CA as an issuing CA, configure autoenrollment of user certificates to install user certificates
on all computers. Ensure that all appropriate domain system containers are configured for
autoenrollment of user certificates either through the inheriting of group policy settings of a parent
system container or explicit configuration.
Summit WM Technical Reference Guide, Software Version 5.1
37

Advertisement

Table of Contents
loading

Table of Contents