Domain Controller Certificate Template Autoenrollment
Certificate template is set up for autoenrollment when its settings are compatible with silent initial enrollment and renewal operations.
Domain controller certificate template autoenrollment. If you need more information about the new certificate templates shipped with a windows 2008 ca you can read this article. Hard coded in this case means it is in the code it is not configured in any local or domain based policy. It replaces the domain controller authentication template. Before you perform this procedure you must configure a server certificate template by using the certificate templates microsoft management console snap in on a ca that is running ad cs.
These include machine computer domain controller and user certificates. All domain controllers are hard coded to automatically enroll for a certificate based on the domain controller template if it is available for enrollment at a certificate authority in the forest. Membership in both the enterprise admins and the root domain s domain admins group is the minimum required to complete this procedure. There are also two windows server 2003 sp2 domain controllers which instead received a domain controller.
Most environments are not normal. Certificate is not set up for autoenrollment when its settings are not compatible with initial certificate enrollment but allow silent certificate renewal operation. Lastly the certificate authority registered to that domain must have the templates issued for the certificates to be auto enrolled. When you install windows 2008 certification authority a new domain controller certificate template named kerberos authentication is available.
Dcs are hard configured to enroll this v1 certificate template through automatic certificate request settings. This combination allows the windows client to enroll users when they log on to their domain or a machine when it boots and keeps them periodically updated between these events. Both domain administrators from the root domain and enterprise administrators for fresh installations of windows server 2003 and newer domains may configure templates. Certificate autoenrollment is based on the combination of group policy settings and version 2 or higher certificate templates.
The following are default settings. Certificate template acls are viewed in the certificate templates. All fine and good every domain joined computer automatically gets a computer certificate issued. In a normal environment the auto enroll will start happening within minutes.