Forum Discussion

charlie4872's avatar
charlie4872
Brass Contributor
Jun 10, 2022

Request Computer Certificate from CA in another AD Forest

Hello I am wondering if there is a way to generate a certificate request for a computer in one AD forest and use the CSR to generate the certificate on the CA in another AD forest. Does anyone know if this is possible? I cannot find documentation on this in my Google searches. Thanks in advance!

  • To auto-enroll it, I think there has to be a Forest trust so that you can use a group for the computer to allow it to auto-enroll. You can always create a CSR manually and let it sign by a CA, doesn't matter if it's in another forest or if it is a public CA even.
  • To auto-enroll it, I think there has to be a Forest trust so that you can use a group for the computer to allow it to auto-enroll. You can always create a CSR manually and let it sign by a CA, doesn't matter if it's in another forest or if it is a public CA even.

Resources