Cross-forest Certificate Enrollment with Windows Server 2008 R2 Beta

Published Jan 24 2020 01:44 PM 2,840 Views
Microsoft

First published on TECHNET on Jan 20, 2009

I am excited to announce the public availability of the Cross-forest Certificate Enrollment with Windows Server 2008 R2 whitepaper.

 

The product team worked hard to make this breakthrough functionality happen in Windows Server 2008 R2 . Now is the time to evaluate cross forest certificate enrollment in your test environment. If you have specific feedback on the whitepaper, feel free to add your comments to this blog entry.

 

From the abstract:
Windows Server 2008 R2 allows enterprises to issue digital certificates from an enterprise Certification Authority (CA) to the clients that are members of a different Active Directory (AD) forest. This process is called cross-forest certificate enrollment. This white paper will explain how the cross-forest certificate enrollment works. It will also provide deployment guidance for new and existing Active Directory Certificate Services (ADCS) deployments. The paper will cover strategies for consolidating existing certificate templates that may be already in use in the enterprise. It will present choices for ongoing management of the cross-forest certificates deployment. A PowerShell script is also provided to facilitate management tasks related to setting up and maintaining cross-forest certificate enrollment environment.

1 Comment
%3CLINGO-SUB%20id%3D%22lingo-sub-1128463%22%20slang%3D%22en-US%22%3ECross-forest%20Certificate%20Enrollment%20with%20Windows%20Server%202008%20R2%20Beta%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1128463%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3E%20First%20published%20on%20TECHNET%20on%20Jan%2020%2C%202009%20%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EI%20am%20excited%20to%20announce%20the%20public%20availability%20of%20the%20%3CA%20href%3D%22http%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fff955842(WS.10).aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%20%3CSPAN%20style%3D%22color%3A%20%230000ff%3B%22%3E%20Cross-forest%20Certificate%20Enrollment%20with%20Windows%20Server%202008%20R2%20%3C%2FSPAN%3E%20%3C%2FA%3E%20whitepaper.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20product%20team%20worked%20hard%20to%20make%20this%20breakthrough%20functionality%20happen%20in%20%3CA%20href%3D%22http%3A%2F%2Fwww.microsoft.com%2Fwindowsserver2008%2Fen%2Fus%2FR2.aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%20%3CSPAN%20style%3D%22color%3A%20%230000ff%3B%22%3E%20Windows%20Server%202008%20R2%20%3C%2FSPAN%3E%20%3C%2FA%3E%20.%20Now%20is%20the%20time%20to%20evaluate%20cross%20forest%20certificate%20enrollment%20in%20your%20test%20environment.%20If%20you%20have%20specific%20feedback%20on%20the%20whitepaper%2C%20feel%20free%20to%20add%20your%20comments%20to%20this%20blog%20entry.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EFrom%20the%20abstract%3A%20%3C%2FSTRONG%3E%20%3CBR%20%2F%3EWindows%20Server%202008%20R2%20allows%20enterprises%20to%20issue%20digital%20certificates%20from%20an%20enterprise%20Certification%20Authority%20(CA)%20to%20the%20clients%20that%20are%20members%20of%20a%20different%20Active%20Directory%20(AD)%20forest.%20This%20process%20is%20called%20cross-forest%20certificate%20enrollment.%20This%20white%20paper%20will%20explain%20how%20the%20cross-forest%20certificate%20enrollment%20works.%20It%20will%20also%20provide%20deployment%20guidance%20for%20new%20and%20existing%20Active%20Directory%20Certificate%20Services%20(ADCS)%20deployments.%20The%20paper%20will%20cover%20strategies%20for%20consolidating%20existing%20certificate%20templates%20that%20may%20be%20already%20in%20use%20in%20the%20enterprise.%20It%20will%20present%20choices%20for%20ongoing%20management%20of%20the%20cross-forest%20certificates%20deployment.%20A%20PowerShell%20script%20is%20also%20provided%20to%20facilitate%20management%20tasks%20related%20to%20setting%20up%20and%20maintaining%20cross-forest%20certificate%20enrollment%20environment.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1128463%22%20slang%3D%22en-US%22%3E%3CP%3EFirst%20published%20on%20TECHNET%20on%20Jan%2020%2C%202009%20I%20am%20excited%20to%20announce%20the%20public%20availability%20of%20the%20Cross-forest%20Certificate%20Enrollment%20with%20Windows%20Server%202008%20R2%20whitepaper.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1128463%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECarstenKinder%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1560143%22%20slang%3D%22en-US%22%3ERe%3A%20Cross-forest%20Certificate%20Enrollment%20with%20Windows%20Server%202008%20R2%20Beta%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1560143%22%20slang%3D%22en-US%22%3E%3CP%3ECan%20somebody%20please%20clarify%20if%20I%20already%20have%20a%20Enterprise%20CA%20in%20an%20Account%20Forest%20can%20I%20establish%20a%20'Cross%20Forest%20Enrollment'%20with%20a%20Resource%20Forest%20and%20maintain%20the%20Enterprise%20CA%20in%20the%20Account%20Forest%20or%20do%20I%20have%20to%20consolidate%20this%20CA%20into%20the%20Resource%20Forest%3F%26nbsp%3B%20%26nbsp%3B%20The%20reason%20I%20am%20asking%20is%20because%20we%20have%26nbsp%3B%20a%20small%20user%20base%20in%20Account%20Forest%20and%20want%20to%20integrate%20these%20into%20an%20AOVPN%20solution%20in%20the%20Resource%20Forest.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%20for%20any%20advise%2Fhelp.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERich%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Feb 20 2020 02:55 PM
Updated by: