MDM and Saparating Web Enrollment from Issuing Certificate Authority ServerHi,<br/><br/>We have a requirement that issuing Certificate Authority server and Web Enrollment component will be hosted on two saparated server<br/> instead of one.<br/><br/>Now technically its achievable but with MDM we have some queries:<br/><br/>1) At the time of installation of Enrollment Server  where to point for Device Certificate Authority and where to point for Server Certificate Authority!<br/><br/>2) How Device will renew the certificate using https?<br/><br/>Any pointers will be appreciated.<br/><br/>-DK<br/><br/>© 2009 Microsoft Corporation. All rights reserved.Fri, 09 Oct 2009 00:55:02 Za0a53f7e-7d8c-4c40-afa4-35425371c1c7http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#a0a53f7e-7d8c-4c40-afa4-35425371c1c7http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#a0a53f7e-7d8c-4c40-afa4-35425371c1c7ideepakkumarhttp://social.technet.microsoft.com/Profile/en-US/?user=ideepakkumarMDM and Saparating Web Enrollment from Issuing Certificate Authority ServerHi,<br/><br/>We have a requirement that issuing Certificate Authority server and Web Enrollment component will be hosted on two saparated server<br/> instead of one.<br/><br/>Now technically its achievable but with MDM we have some queries:<br/><br/>1) At the time of installation of Enrollment Server  where to point for Device Certificate Authority and where to point for Server Certificate Authority!<br/><br/>2) How Device will renew the certificate using https?<br/><br/>Any pointers will be appreciated.<br/><br/>-DK<br/><br/>Thu, 02 Jul 2009 16:03:43 Z2009-07-02T16:03:43Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#1e11af12-9920-4f48-b766-9fe74613a9e9http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#1e11af12-9920-4f48-b766-9fe74613a9e9Andreas Hellandhttp://social.technet.microsoft.com/Profile/en-US/?user=Andreas%20HellandMDM and Saparating Web Enrollment from Issuing Certificate Authority ServerIt's no problem having the CA and the enrollment server on different servers.<br/><br/>1. You choose both of these during the setup wizard for the enrollment server. At least if the enrollment server is the first role you install (which I believe I read is the recommended way). The server CA is only used by the installer though - you don't have to let SCMDM do these certificates for you. (A lot easier though of course.) As long as you provide the full FQDN and instance name for the CA this should work out-of-the-box.<br/><br/>2. The devices will attempt to renew their certificates by communicating directly to the CA, and the enrollment server is not involved in this process.Thu, 02 Jul 2009 16:37:42 Z2009-07-02T16:37:42Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#5142a083-0b40-4ecd-8832-569f519e2286http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#5142a083-0b40-4ecd-8832-569f519e2286Wayne Phillips.http://social.technet.microsoft.com/Profile/en-US/?user=Wayne%20Phillips.MDM and Saparating Web Enrollment from Issuing Certificate Authority Server<p>You might have issues using a Device Certificate Authority and a Server Certificate Authority ! For Client Certificate Authentication to work you need to have the server certificates and the device certificates issue by the same CA or subordinate CA. I think the certificates need to be from the same trusted source so you might find that they have to be the same CA.</p> <p>Cheers Wayne<br/>Airloom</p>Fri, 03 Jul 2009 00:02:22 Z2009-07-03T00:02:22Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#4d3a45b8-5446-4312-848c-470ffe0c9667http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#4d3a45b8-5446-4312-848c-470ffe0c9667ideepakkumarhttp://social.technet.microsoft.com/Profile/en-US/?user=ideepakkumarMDM and Saparating Web Enrollment from Issuing Certificate Authority Server<p class=MsoNormal style="margin:0in 0.1in 6pt 0.3in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">Andreas/Wayne,<br/><br/>Thanks for your inputs.<br/><br/>The question remains though let me rephrase for you:<br/><br/>1) Now At the time of Enrollment Server installation we have to specify <br/>  <br/>     Device Certificate Authority - <strong><span style="text-decoration:underline">Given scenario where I have Web enrollment and ICA on separate system what should I mention here?</span></strong><br/>     Server Certificate Authority - Given scenario I know that we need to specify the ICA itself not the web enrollment server.<br/><br/>2) Now if for device Certificate authority we specify the ICA itself  [Not the web enrollment Server] the how device will renew the certificate [ As Andreas mentioned device will hit ICA directly, which actually make sense] and do we have any reason keeping web enrollment server?<br/><br/><br/>Many thanks for the help and time.<br/><br/>-DK</span></p>Fri, 03 Jul 2009 02:18:26 Z2009-07-03T02:18:26Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#7b49204e-266d-48c8-9334-6a05da11db07http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#7b49204e-266d-48c8-9334-6a05da11db07Wayne Phillips.http://social.technet.microsoft.com/Profile/en-US/?user=Wayne%20Phillips.MDM and Saparating Web Enrollment from Issuing Certificate Authority Serverideepakkumar,<br/><br/>I’m guessing ICA means Intermediate Certificate Authority.<br/> <blockquote><span style="line-height:115%;font-family:'Verdana', 'sans-serif';color:black;font-size:8pt">Andreas/Wayne,<br/><br/>Thanks for your inputs.<br/></span><br/>The question remains though let me rephrase for you:<br/><br/>1) Now At the time of Enrollment Server installation we have to specify<br/><br/>Device Certificate Authority – <strong><span style="color:#c00000">Enter your Intermediate Certificate Authority server.</span></strong> <br/><br/>Server Certificate Authority – <strong><span style="color:#c00000">Enter your Intermediate Certificate Authority server.</span></strong> <br/><br/>2) Now if for device Certificate authority we specify the ICA itself [Not the web enrollment Server] the how device will renew the certificate [ As Andreas mentioned device will hit ICA directly, which actually make sense] and do we have any reason keeping web enrollment server? <br/><br/><strong><span style="color:#c00000">Yes you need the web enrolment server… The enrolment server requests the initial client certificate on behalf of the user. I’m a bit hazy on the renewal process, so I’d have to agree with Andreas. The devices renews the certificate with the CA directly.</span></strong> <br/><br/>Many thanks for the help and time.<br/><br/>-DK<br/></blockquote> <br/>Cheers Wayne<br/>AirloomFri, 03 Jul 2009 03:21:36 Z2009-07-03T03:22:22Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#1bf5fcb9-0a89-426a-b3a2-9a84a3203f53http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#1bf5fcb9-0a89-426a-b3a2-9a84a3203f53ideepakkumarhttp://social.technet.microsoft.com/Profile/en-US/?user=ideepakkumarMDM and Saparating Web Enrollment from Issuing Certificate Authority Server<p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">Thanks for the quick reply Wayne.</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"> </span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">Even we are not clear about the device renewal process as per given scenario and questioning the relevance of Web Enrollment Server! </span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">Now what I’ve done ; After installing MDM enrollment server and pointing to ICA at the time of installation, I fired  cmdlet<br/></span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"><br/>Get-EnrollmentServicelog</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"> </span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">And looked for “RenewalInfo” which points to the ICA not the web enrollment [As expected]</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">&quot;RenewalInfo&quot;&gt;&lt;par</span><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">m name=&quot;ServerName&quot; value=&quot;ICA.Domain&quot; /&gt;&lt;parm name=&quot;Template&quot; value=&quot;SCMDMMo</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"><span style="">                           </span>bileDevice (InstanceName)&quot; /&gt;&lt;parm name=&quot;RequestPage&quot; valu</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"><span style="">                           </span>e=&quot;/certsrv/certfnsh.asp&quot; /&gt;&lt;parm name=&quot;PickupPage&quot; </span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"><span style="">                </span><span style="">           </span>value=&quot;/certsrv/certnew.cer&quot; /&gt;&lt;parm name=&quot;NoSSL&quot; va</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"><span style="">                           </span>lue=&quot;1&quot; datatype=&quot;boolean&quot; /&gt;</span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"> </span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt">Now another question is device is not going to hit web enrollment then how device will renew the cert based on above information. Will device use PKCS10 for renewal?<br/></span></p> <p class=MsoNormal style="margin:0in 0.1in 6pt 0in"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt"><br/>-DK</span></p>Fri, 03 Jul 2009 06:25:53 Z2009-07-03T06:25:53Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#8ef52365-3bac-432b-ae77-396054768c04http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#8ef52365-3bac-432b-ae77-396054768c04Andreas Hellandhttp://social.technet.microsoft.com/Profile/en-US/?user=Andreas%20HellandMDM and Saparating Web Enrollment from Issuing Certificate Authority Server<p>The device should try to contact the ICA before the certificate expires, and obviously it will fail if the device is not able to bring up the VPN tunnel or in other ways not reach the ICA. The device does not create a file, or anything like that and will try to post directly to the HTTPS interface of the ICA. I don't know if this is in PKCS10 or some other format. So it basically works the same way as when you try renewing an SSL cert on a server, or a desktop computer.</p>Fri, 03 Jul 2009 08:04:44 Z2009-07-03T08:04:44Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#f94dea3a-bb21-4470-801f-7b464e5cc227http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/a0a53f7e-7d8c-4c40-afa4-35425371c1c7#f94dea3a-bb21-4470-801f-7b464e5cc227ideepakkumarhttp://social.technet.microsoft.com/Profile/en-US/?user=ideepakkumarMDM and Saparating Web Enrollment from Issuing Certificate Authority ServerOkie.<br/><br/>Thanks for the information Andreas :-)<br/><br/>Will capture the test results to share with you experts.<br/><br/>Thanks.<br/><br/>-DKSun, 05 Jul 2009 15:42:57 Z2009-07-05T15:42:57Z