Manage internet based clients certificates

%3CLINGO-SUB%20id%3D%22lingo-sub-1090858%22%20slang%3D%22en-US%22%3EManage%20internet%20based%20clients%20certificates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1090858%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20we%20installed%20our%20SCCM%20environment%3CSPAN%3E%20a%20few%20years%20ago%3C%2FSPAN%3E%2C%20we%20used%20sha1%20as%20an%20algorithm%20for%20the%20certificate%20templates.%20We%20since%20than%20upgraded%20our%20domain%20controller%20which%20hosts%20the%20CA%20to%20sha256%20as%20part%20of%20upgrading%20our%20active%20directory%20to%202016.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20setup%20was%20listening%20on%20both%20http%20and%20https%20on%20our%20intranet%20and%20https%20on%20internet%20facing%20MP.%20Since%20we%20use%20Bitlocker%20on%20our%20computers%20and%201910%20is%20integrated%20with%20MBAM%20we%20wanted%20to%20migrate%20our%20environment%20to%20https%20only.%20the%20transition%20went%20smooth%20mostlywhere%20our%20computers%20that%20are%20domain%20joined%20use%20the%20new%20sha256%20certificates%20to%20talk%20to%20our%20MP's%20and%20the%20policy%20%22Automatic%20certificate%20management%22%20is%20enabled.%20So%20even%20when%20those%20computers%20are%20on%20the%20internet%20they%20are%20able%20to%20connect%20to%20the%20DMZ%20MP%20andreport%20%2B%20get%20the%20deployments.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20problem%20is%20with%20our%20workgroup%20computers.%20I%20didn't%20deploy%20the%20new%20trusted%20root%20CA%20to%20the%20workgroup%20computers%20which%20means%20that%20it%20gets%20invalid%20certificate.%20I%20understand%20that%20I%20will%20need%20to%20manually%20deploy%20new%20certificates%20to%20these%20computers%20but%20now%20I'm%20facing%20another%20problem%3A%20The%20next%20time%20I'll%20be%20required%20to%20renew%20my%20CA%20certificate%20I%20will%20have%20to%20reissue%20new%20certificate%20for%20those%20computers%20because%20the%20chain%20will%20be%20broken.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20can%20I%20automate%20this%20process%3F%20I%20want%20to%20know%20when%20an%20issued%20certificate%2C%20be%20it%20for%20a%20domain%20joined%20or%20workgroup%2C%20intranet%20or%20internet%2C%20server%20or%20client%20or%20trusted%20root.%20It%20will%20be%20renewed%20automatically%20after%20the%20CA%20is%20renewing%20it's%20certificate%20or%20a%20clientcertificate%20is%20expired.%3C%2FP%3E%3CP%3EI%20understand%20that%20renewing%20IIS%20and%20DP%20certificate%20is%20a%20manual%20thing%20but%20beyond%20that%20I%20don't%20believe%20people%20are%20manually%20renew%20their%20IBC%20computers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERahamim.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1090858%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESite%20Setup%20and%20Client%20Deployment%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Frequent Contributor

Hi all,

 

When we installed our SCCM environment a few years ago, we used sha1 as an algorithm for the certificate templates. We since than upgraded our domain controller which hosts the CA to sha256 as part of upgrading our active directory to 2016.

 

Our setup was listening on both http and https on our intranet and https on internet facing MP. Since we use Bitlocker on our computers and 1910 is integrated with MBAM we wanted to migrate our environment to https only. the transition went smooth mostlywhere our computers that are domain joined use the new sha256 certificates to talk to our MP's and the policy "Automatic certificate management" is enabled. So even when those computers are on the internet they are able to connect to the DMZ MP andreport + get the deployments.

 

Our problem is with our workgroup computers. I didn't deploy the new trusted root CA to the workgroup computers which means that it gets invalid certificate. I understand that I will need to manually deploy new certificates to these computers but now I'm facing another problem: The next time I'll be required to renew my CA certificate I will have to reissue new certificate for those computers because the chain will be broken.

 

How can I automate this process? I want to know when an issued certificate, be it for a domain joined or workgroup, intranet or internet, server or client or trusted root. It will be renewed automatically after the CA is renewing it's certificate or a clientcertificate is expired.

I understand that renewing IIS and DP certificate is a manual thing but beyond that I don't believe people are manually renew their IBC computers.

 

Thanks in advance,

 

Rahamim.

0 Replies