Menu
InformatiWeb Pro
  • Index
  • System admin
  • Virtualization

Login

Registration Password lost ?
FR
  • Windows Server
    • WMS 2012
    • WS2012 R2
    • WS2016
  • Citrix
    • Citrix NetScaler Gateway
    • Citrix XenApp / XenDesktop
    • Citrix XenServer
  • VMware
    • VMware ESXi
    • VMware vSphere
    • VMware Workstation
  • Microsoft
    • Hyper-V
  • RAID
    • Adaptec SmartRAID
  • UPS
    • APC Back-UPS Pro
  • InformatiWeb Pro
  • System admin
  • Windows Server
  • Courses
  • Learn how to use Active Directory Certificate Services (AD CS) on WS 2016
  • Create an enrollment agent
19 / 21
  • Backup and restore a certificate authority (CA)
  • Buy smart cards and log in via them

Create an enrollment agent to enroll certificates on behalf of someone else on Windows Server 2016

  • Windows Server
  • 12 January 2024 at 10:03 UTC
  • InformatiWeb
  • 3/3
Previous page

6. Restrict enrollment agents

Since Windows Server 2008, you have the ability to restrict what enrollment agents can do (if desired).

To do this, in your "Certification Authority" console, right-click "Properties".

In the properties window that appears, go to the "Enrollment Agents" tab.
As you can see, by default, the option "Do not restrict enrollment agents".

Permissions are therefore managed only on the certificate templates you create and whether or not a user has a currently valid enrollment agent certificate.

If you select the "Restrict enrollment agents" option, a warning will be displayed to warn you that these restrictions only apply to certification authorities on Windows Server 2008 or later.

Plain Text

Restrictions on delegated enrollment agents can only be enforced on Windows Server 2008 CAs and later.
Before designating delegated enrollment agents, make sure your enrollment agent policy is appropriate for your PKI environment.

As you can see, by default, all enrollment agents can enroll certificates using any certificate templates for which they have "Enroll" permission to issue them to any users they wish.
To allow only some enrollment agents to enroll certificates through your CA, start by clicking "Add" for the 1st section (Enrollment Agent).

Warning : for each of the 3 sections available in this tab, you must always add at least one other option if you want to delete the one present by default.
Otherwise, the option "Do not restrict enrollment agents" will be selected automatically and you will lose the changes made in the various sections of this tab.

Provide the name of the enrollment agent or a group of enrollment agents (if applicable) that you want to allow to enroll certificates through your certification authority, then click OK.

The added enrollment agent or enrollment agent group appears in the list of enrollment agents authorized to enroll certificates through your certification authority.

Now that you've restricted the authorized enrollment agents, remove the default "Everyone" group from this list.

To prevent your enrollment agents from issuing certificates using whatever certificate templates they have access to, you can limit the templates they can use.
To do this, for the "Certificate Templates" section, click on the "Add" button.

Select the certificate template that your agents can issue to your users and click OK.

Once you've added the template(s) you want to allow for certificate enrollment by your enrollment agents, remember to remove the default "<All>" value.

Finally, you can choose which users or groups of users your agents can enroll certificates for.
To do this, for the "Permissions" section, click on "Add".

Specify the name of a user or user group and click OK.

The desired user or group of users appears in the list of permissions.
As before, don't forget to remove the "Everyone" group so that the restriction is correctly applied.

In our case, our "IWAgent" agent will only be able to issue certificates based on our "Smartcard Logon v2" certificate template to all users in our Active Directory domain.

Share this tutorial

Partager
Tweet

To see also

  • SafeNet Authentication Client (SAC) - Installation and overview

    Articles 1/26/2024

    SafeNet Authentication Client (SAC) - Installation and overview

  • What is encryption and how does it work ?

    Articles 9/8/2023

    What is encryption and how does it work ?

  • WS 2016 - AD CS - Backup and restore a certificate authority (CA)

    Windows Server 12/29/2023

    WS 2016 - AD CS - Backup and restore a certificate authority (CA)

  • WS 2016 - AD CS - Buy smart cards and log in via them

    Windows Server 1/19/2024

    WS 2016 - AD CS - Buy smart cards and log in via them

Comments

No comment

Share your opinion

Pinned content

  • Software (System admin)
  • Linux softwares
  • Our programs
  • Terms and conditions
  • Share your opinion

Contact

  • Guest book
  • Technical support
  • Contact

® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.

Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.