-
On the domain controller running the Windows Server 2003 console, click Start, Programs, Administrative Tools, Certification Authority.
-
Expand the name of your CA, and then click Certificate Templates.
-
Right-click Certificate Templates, and click Manage to load the Certificates Templates management console.
-
In the results pane, right-click the entry that displays Web Server in the Template Display Name column, and then click Duplicate Template.
-
In the Properties of New Template dialog box, on the General tab, enter a template name for the AMT provisioning certificate template, such as ConfigMgr AMT Provisioning.
-
Click the Request Handling tab, and select Allow private key to be exported.
-
Click the Extensions tab, make sure Application Policies is selected, and then click Edit.
-
In the Edit Application Policies Extension dialog box, click Add.
-
In the Add Application Policy dialog box, click New.
-
In the New Application Policy dialog box, type AMT Provisioning in the Name field, and then type the following number for the Object identifier: 2.16.840.1.113741.1.2.3.
-
Click OK, and then click OK in the Add Application Policy dialog box.
-
Click OK in the Edit Application Policies Extension dialog box.
-
In the Properties of New Template dialog box, you should now see the following listed as the Application Policies description: Server Authentication and AMT Provisioning.
-
Click the Security tab, and remove the Enroll permission from the security groups Domain Admins and Enterprise Admins.
-
Click Add, enter ConfigMgr Out of Band Service Points in the text box, and then click OK.
-
Select the following Allow permissions for this group: Read and Enroll.
-
Click OK, and close the Certificate Templates administrator console, certtmpl – [Certificate Templates].
-
In Certification Authority, right-click Certificate Templates, click New, and then click Certificate Template to Issue.
-
In the Enable Certificate Templates dialog box, select the new template you have just created, ConfigMgr AMT Provisioning, and then click OK.
Note |
|
If you cannot complete steps 18 or 19, check that you are using the Enterprise Edition of Windows Server 2003. Although you can configure templates with Windows Server Standard Edition and Certificate Services, you cannot deploy certificates using modified certificate templates unless you are using the Enterprise Edition of Windows Server 2003. |
-
Do not close Certification Authority.
-
On the member server, load Internet Explorer and connect to the Web enrollment service with the address http://<server>/certsrv, where <server> is the name or IP address of the enterprise CA.
-
On the Welcome page, select Request a certificate.
-
On the Request a Certificate page, select advanced certificate request.
-
On the Advanced Certificate Request page, select Create and submit a request to this CA.
-
On the Advanced Certificate Request page, specify the following:
-
Select ConfigMgr AMT Provisioning for the Certificate Template.
Note |
|---|
|
If you cannot see this certificate template displayed, check that you restarted the member server (if it was running) after you configured the security group in the earlier procedure. |
-
Type the fully qualified domain name (FQDN) of the out of band service point in the Name field.
-
Type a contact e-mail address for your company in the E-Mail field.
-
Type the name of your company in the Company field.
-
Type the name of your company's department in the Department field.
-
Type your company's city name in the City field.
-
Type your company's state (full name or abbreviation) in the State field.
-
Type your company's country code and region in the Country/Region field.
-
Under the section Key Options, enable Store certificate in the local computer certificate store.
-
Under the section Additional Options, click PKC10, click Save request to file, and then type in the full path and name for the offline certificate request file, such as C:\certreq_amt_<servername>.txt, where <servername> is the host name of the out of band service point.
-
Type your choice of name for Friendly Name, such as ConfigMgr AMT Provisioning Certificate for <FQDN>, where <FQDN> is the fully qualified name of the out of band service point.
-
Click Save.
-
Click Yes when prompted in the Potential Scripting Violation dialog box.
-
Click Yes when prompted in the Certificate Enrollment dialog box.
-
Click OK to confirm that the request was saved to file.
-
Exit Internet Explorer.
-
Send the file to the external CA using any instructions that they provide.
-
When you receive the AMT provisioning certificate from the CA, it is likely to be in an e-mail format. Copy the text and paste it into Notepad, saving the file with a .p7b extension. Make sure that you can access the file from the member server.
-
On the member server, click Start, click Run, type MMC in the Run dialog box, and then click OK.
-
In the empty console, click File, and then click Add/Remove Snap-in.
-
In the Add or Remove Snap-ins dialog box, click Add.
-
Select Certificates from Available snap-ins, and then click Add.
-
In the Certificates snap-in dialog box, click Computer account, and then click Next.
-
In the Select Computer dialog box, ensure that the option Local computer: (the computer this console is running on) is selected, and then click Finish.
-
In the Add Standalone Snap-in dialog box, click Close.
-
In the Add or Remove Snap-ins dialog box, click OK.
-
In the console, expand Certificates (Local Computer).
-
Expand Personal, and then right-click Certificates.
-
Click All Tasks, and click Import.
-
In the Welcome to the Certificate Import Wizard page, click Next,
-
On the File to Import page, click Browse to navigate to the saved file with the .p7b extension, and then click Next.
-
Select Place all certificates in the following store, click Next, and then click Finish.
-
Press F5 to refresh, and you should now see the provisioning certificate displayed.
-
Do not close Certificates (Local Computer).
The AMT provisioning certificate from an external CA is now installed and is ready to be prepared for the out of band management component.