LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-19-2012, 04:20 AM   #1
harshanahnd
LQ Newbie
 
Registered: Mar 2012
Posts: 3

Rep: Reputation: Disabled
Certificate auto enrollment for Linux clients


Hi,

I have some linux clients connected to a MS domain controller. And I need to get certificates autoenrolled for them from Microsoft Active Directory Certificate Services. Is there a linux tool that I can use to get this thing done?

Currently AD authentication for Linux hosts is done through a third party tool.

Any help on this is highly appreciated.

Thank you.
 
Old 03-19-2012, 09:56 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by harshanahnd View Post
Hi,
I have some linux clients connected to a MS domain controller. And I need to get certificates autoenrolled for them from Microsoft Active Directory Certificate Services. Is there a linux tool that I can use to get this thing done?

Currently AD authentication for Linux hosts is done through a third party tool.
You don't tell us what version/distro of Linux, what version of Windows is on the DC, or what "third party tool" you're using, so we have no idea what you've got to work with, what you've done/tried, or what error(s) you get. So, there's little we can tell you, unless you provide details.

From what I've read, you may be able to use LDAP to do this, but if you're using Microsoft, have you asked their tech-support folks?
 
Old 03-19-2012, 08:40 PM   #3
harshanahnd
LQ Newbie
 
Registered: Mar 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
Hi,
I have Microsoft Active Directory running on Windows server 2008 R2. And my certificate services also running on Windows server 2008 R2. The linux distributions that are connected to the AD is RedHat Enterprise Linux (RHEL 6.0 and 5.5) and Suse Linux Enterprise Server (SLES 11 and 10). The AD authentication for the linux clients is done through Quest software Authentication Services.

I need to find out linux clients that supports Windows Client Certificate Enrollment Protocol and Certificate Auto enrollment System Overview according to the Microsoft TechNet forums.

I have tested the possibilities of using SCEP protocol for this scenario. What I tested is SSCEP. Since SCEP is by design for issue certificates for the network devices, Microsoft SCEP service does not perform a domain authentication prior to issuing a certificate. I need to perform a domain authentication prior to issuing a certificate.

Any help or hint on this scenario is highly appreciated.

Thank you.
 
Old 03-20-2012, 10:36 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by harshanahnd View Post
Hi,
I have Microsoft Active Directory running on Windows server 2008 R2. And my certificate services also running on Windows server 2008 R2. The linux distributions that are connected to the AD is RedHat Enterprise Linux (RHEL 6.0 and 5.5) and Suse Linux Enterprise Server (SLES 11 and 10). The AD authentication for the linux clients is done through Quest software Authentication Services.

I need to find out linux clients that supports Windows Client Certificate Enrollment Protocol and Certificate Auto enrollment System Overview according to the Microsoft TechNet forums.

I have tested the possibilities of using SCEP protocol for this scenario. What I tested is SSCEP. Since SCEP is by design for issue certificates for the network devices, Microsoft SCEP service does not perform a domain authentication prior to issuing a certificate. I need to perform a domain authentication prior to issuing a certificate.
Well, since you're in an environment that's vendor-supported, I'll again suggest contacting your vendors. Microsoft, RedHat, and Novell, in this case, since you're using pay-for products from each of them.

You mention the SCEP software, which you know won't do what you want. Again, LDAP can be used in this situation, from what I've read, but I've not actually done it, which is why contacting Microsoft will be a good idea. They'll be able to tell you where certificates are, how to generate them, etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN connects, can't ping or RDP from linux clients, but Win clients are fine davidbell.mscf Linux - Networking 1 02-28-2011 05:11 PM
LXer: IRC Clients for Linux Part 2: List of 5 CLI Clients LXer Syndicated Linux News 0 09-17-2008 05:20 PM
LXer: IRC Clients for Linux Part 1: List of 6 GUI Clients LXer Syndicated Linux News 0 09-12-2008 04:40 PM
Can I retrieve certificate expiry date from an openssl certificate (command line) davee Linux - Security 1 07-21-2006 10:28 AM
Auto Logon clients ishmael437 Linux - Security 1 12-11-2002 03:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 05:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration