J
Jeff
I am interested in using a GP or script to push an
Internet Explorer (exported) PFX Certificate that is
issued by web sites outside of the domain.
As a bank we use several web enabled companys for
performing tasks, such as ordering checks from Deluxe.
Deluxe issues a Certificate so that specific users can
access thier site to order checks. The certificates are
installed through Internet Explorer and then we are asked
to export the certificate as a PFX file which has the
user's password. The reason for this is so that if the
machine breaks, or the user moves to another workstation,
we can re-import the certificate and all is well.
Now, if a user accesses several workstations on the
domain, you guessed it, I have to go to each workstation
and import the certificate. Also, when we upgrade our
machines, we must do the same, or when the certificate
expires, or when the user rights are changed and a new
certificate is issued.
What I am interested in doing is pushing the PFX (not a
CER) certificate on a per user basis, so that no matter
where they sign in or what branch they go to, the
certificate is installed and ready for use. An added
bonus would be the ability to revoke the certificate when
a user leaves the organization.
This is what I have looked into:
This link was referenced
http://www.microsoft.com/windows2000/techinfo/planning/sec
urity/mappingcerts.asp
From the Chat area, I had already looked at a similar
doc, and learned that the Exported PFX could not be
imported on the Name Mappings for the User in Active
Directory.
Any ideas how I can accomplish this, it would certainly
same me a lot of time...!
Jeff Smyrski
Internet Explorer (exported) PFX Certificate that is
issued by web sites outside of the domain.
As a bank we use several web enabled companys for
performing tasks, such as ordering checks from Deluxe.
Deluxe issues a Certificate so that specific users can
access thier site to order checks. The certificates are
installed through Internet Explorer and then we are asked
to export the certificate as a PFX file which has the
user's password. The reason for this is so that if the
machine breaks, or the user moves to another workstation,
we can re-import the certificate and all is well.
Now, if a user accesses several workstations on the
domain, you guessed it, I have to go to each workstation
and import the certificate. Also, when we upgrade our
machines, we must do the same, or when the certificate
expires, or when the user rights are changed and a new
certificate is issued.
What I am interested in doing is pushing the PFX (not a
CER) certificate on a per user basis, so that no matter
where they sign in or what branch they go to, the
certificate is installed and ready for use. An added
bonus would be the ability to revoke the certificate when
a user leaves the organization.
This is what I have looked into:
This link was referenced
http://www.microsoft.com/windows2000/techinfo/planning/sec
urity/mappingcerts.asp
From the Chat area, I had already looked at a similar
doc, and learned that the Exported PFX could not be
imported on the Name Mappings for the User in Active
Directory.
Any ideas how I can accomplish this, it would certainly
same me a lot of time...!
Jeff Smyrski