Certificate Dispursment and authentication for mobile devices using NPS, NDES, and EAP-TLS through MDM Mechanism.
so reading through of these other items eap-tls , wanted input on situation.
having hardest time trying validation work @ nps setup. tried looking @ minimal requirements eap-tls server , client not familiar enough whole process understand missing something.
i have created 2008 r2 enterprise ca nps , ndes server. split parts out later right want keep them together.
have made ca issuing root-ca 2003 enterprise server. have installed web enrollment part well.
set nps settings simplest can, conditions based on ad group apart of. created cert ipsec offline cert trying to follow criteria given me our mdm ndes deployment. has client authentication in it. set signing , encryption , subject name set supplied in request.
what want able have ndes communicate mdm has scep application can login scep admin website, cert device has authenticated mdm using ad creds, , allow connect hte wireless hosted on meracki ap's pointed @ 2008 r2 nps.
any how tos, input, 2 cents, how it's 1 appreciated. have had ms on phone prove me cert can used computer , least of concerns right now.
thanks in advance.
the following steps described overall procedure to working:
1. create user account each device want enroll in ad
2. create suitable certifiacte template used scep/ndes, make sure published in ca , configured on ndes
3. make sure ca certificate trusted on device revieve client certificate via scep/ndes
4. deploy/issue client certifiacet device using user account/creds created in step 1
the following blog post http://blogs.technet.com/b/pki/archive/2012/02/27/ndes-and-ipads.aspx on windows pki blog describes above steps in more details including troubleshooting steps.
/hasain
Windows Server > Security
Comments
Post a Comment