Certificates
11 TopicsAnnouncement: How to Request a Certificate with a Custom Subject Alternative Name
First published on CLOUDBLOGS on Apr 21, 2010 [Today's post comes from Carol Bailey] I'm really pleased to be able to announce a recent publication from the Certificate Services documentation team that will help our customers running Configuration Manager in native mode: How to Request a Certificate With a Custom Subject Alternative Name.5.5KViews0likes0CommentsKnown Issue: Logging Information for Native Mode Certificate Selection
First published on CLOUDBLOGS on Dec 15, 2009 [Carol Bailey has contributed today's post]A couple of issues recently came to our attention from the TechNet forums with regard to native mode certificate selection when there is more than one available certificate that could be used:When a certificate in the certificate store has expired, we log this and Trace32 highlights it as an error, which might be interpreted that it is this certificate that is selected.370Views0likes0CommentsUpdated Blog Post for How to Publish the CRL on a Separate Web Server – for Delta CRLs
First published on CLOUDBLOGS on Aug 13, 2009 [Carol Bailey has updated her previous post "How to Publish the CRL on a Separate Web Server"] We've recently updated our blog post for publishing the CRL on a separate Web server because the instructions were missing the variable in the paths, which is needed for delta CRLs.445Views0likes0CommentsRecommendations for PKI Key Lengths and Validity Periods with Configuration Manager
First published on CLOUDBLOGS on Jun 12, 2009 [Today's post is provided by Carol Bailey]I sometimes get questions from customers about values to set for the key sizes and validity periods for the certificates required for native mode and out of band management in Configuration Manager.19KViews0likes0CommentsRequesting an AMT Provisioning Certificate with Windows Server 2008 CA
First published on CLOUDBLOGS on Feb 25, 2009 [Today's post is provided by Carol Bailey]With the December documentation update for the Configuration Manager library, we posted a new step-by-step guide for out of band management, to help customers deploy the PKI certificates with a Windows Server 2008 CA (http://technet.2.9KViews0likes0CommentsHow to Renew the Site Server Signing Certificate (Microsoft Certificate Services)
First published on CLOUDBLOGS on Feb 11, 2009 [Today's post is brought to you by Carol Bailey]Have you tried to renew the existing site server signing certificate for a native mode site, and wondered how to do this without creating a new certificate? This post provides a procedure to do this that is suitable for when the site server is on either Windows Server 2003 or Windows Server 2008, and your PKI uses Microsoft Certificate Services.22KViews0likes0CommentsDoes Configuration Manager Native Mode Have to Use a Single CA Hierarchy?
First published on CLOUDBLOGS on Jan 28, 2009 [Today's post is contributed by Carol Bailey]We've seen this question come up a few times, and the simple answer is no - as long as the communicating computers have a trust in common, and the correct certificates are used, native mode works just fine.641Views0likes0Comments