Windows 10: setting up CES and CEP PKI in a trusted forest scenario

Discus and support setting up CES and CEP PKI in a trusted forest scenario in Windows 10 Software and Apps to solve the problem; I have two domains with a two-way forest trust. I want computer accounts in DomainB to enroll for computer client auth certificates from the two-tier... Discussion in 'Windows 10 Software and Apps' started by NickSTL77, Feb 25, 2023.

  1. NickSTL77 Win User

    setting up CES and CEP PKI in a trusted forest scenario


    I have two domains with a two-way forest trust. I want computer accounts in DomainB to enroll for computer client auth certificates from the two-tier Windows CA in DomainA. I configured a certificate cert template in the issuing CA for this and gave Read and Enroll rights to the computer in DomainB.I configured the issuing CA in DomainA for the Certificate Enrollment Policy Web Service and Certificate Enrollment Web Service according to the Microsoft documentation. CEP and CES are using Kerberos authentication using a domain service account with an SPN and configured for Kerberos delegati

    :)
     
    NickSTL77, Feb 25, 2023
    #1
  2. KaneKW Win User

    Error found on CEP and CES for enrolling non-domain joined computers for certificates

    Hi;

    I am configuring CES/CEP on Windows Server 2012 R2 for non domain joined PC to use User Name and Password to authenticate the wifi which is configured with NPS server.

    I followed the steps here

    Install and Configure Certificate Enrolment Policy Web Service | PeteNetLive

    and

    https://techcommunity.microsoft.com...lling-non-domain-joined-computers/ba-p/397821

    to configure with using user name and password (domain account) for authentication

    however, when I test it, I got the "remote end point could not process the request 0x803d000f error.

    The CES/CEP server is running on the other server, not the same as CA server.

    How can I fix the issue?

    Except the links above, any other reference for CES/CEP configuration on Windows Server 2012R2 for non domain joined PC.

    thanks in advance.
     
    KaneKW, Feb 25, 2023
    #2
  3. Hub-Site Win User
    root forest -Trust

    Hi all,

    hope someone can shed some light on this issue. In our environment we have Windows Server 2003 DC on domain (A). and DC 2012 R2 Domain (B). these two are not same forest root.

    we setup one-way Trust (Type) Forest trust transitive= Domain B (2012 R2 DC) trusted Domain A (2003 DC)=

    -Direction of trust- Outgoing

    -Transitivity of trust- forest transitive

    -Validated successful.

    -Name suffix Routing setup for Domain.local B forest.

    -authentication Forest wide - forest wide authentication

    validated = passed (no problem here)

    adding users to domain B group = failed error stated (some of the object names cannot be shown in their user-friendly name form , this can happen if the object is from an external domain and that domain is not available to translate the object name)



    this happened after selected some users from domain A, which mean I did able browsing on domain-A of AD.

    If we tried two way trust then everything seemed OK, we were able successfully added some users. so no issue on two-way trust.

    if two way-trust is fine, that's rule out DNS, right?

    thank you every much in advance.
     
    Hub-Site, Feb 25, 2023
    #3
  4. changari Win User

    setting up CES and CEP PKI in a trusted forest scenario

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Feb 25, 2023
    #4
Thema:

setting up CES and CEP PKI in a trusted forest scenario

Loading...
  1. setting up CES and CEP PKI in a trusted forest scenario - Similar Threads - setting CES CEP

  2. setting up CES and CEP PKI in a trusted forest scenario

    in Windows 10 Gaming
    setting up CES and CEP PKI in a trusted forest scenario: I have two domains with a two-way forest trust. I want computer accounts in DomainB to enroll for computer client auth certificates from the two-tier Windows CA in DomainA. I configured a certificate cert template in the issuing CA for this and gave Read and Enroll rights to...
  3. Certificate/PKI/Smart Card Logon

    in Windows 10 Gaming
    Certificate/PKI/Smart Card Logon: Hello,I am having an issue with authenticating users in an air gapped network after a patch. Any users prior created in AD prior to May 2022, can still authenticate with the server. However, if I create a new test account and attach my X.509 to altSecurityID attribute, I get...
  4. Windows acting as UP key is stuck but only in certain scenarios.

    in Windows 10 Gaming
    Windows acting as UP key is stuck but only in certain scenarios.: Hey!So basically after a windows update the other day, my PC is acting as if the UP key is stuck, however [important note] it does not do it when I use any apps, using Chrome or when I'm browsing folders on the PC. It only does it when I'm trying to use the menu bar, when I...
  5. Grant shared mailbox access to users from trusted forest

    in Windows 10 Customization
    Grant shared mailbox access to users from trusted forest: Hi I am unable to grant shared mailbox access to users in another trusted forest. I've used the command "Add-MailboxPermission sharedmailboxalias -User "DomainA\UserA" -AccessRights FullAccess" but is getting the error "User or group wasn't found. Please make sure you've...
  6. saving multiple scenarios of screen display settings

    in Windows 10 Customization
    saving multiple scenarios of screen display settings: Because my laptop screen and external monitor are different resolutions which is a nightmare that Dell didn't warn me about, I need to have three different display settings scenarios: one for when I have the external monitor connected, one for when I only have the laptop...
  7. Enterprise PKI role ?

    in AntiVirus, Firewalls and System Security
    Enterprise PKI role ?: We are Windows shop with Active Directory environment and 400 Windows 10 Clients. We have Six Domain Controllers DC, all are part of one AD Forest, one DC is windows 2008r2 and remaining are windows 2012 standard. The only windows 2008 DC is showing Enterprise PKI role...
  8. DST - Testing scenarios

    in Windows 10 Customization
    DST - Testing scenarios: As developer, I am sometimes in the situation that I need DST "now" to test the behavior of a system/software ... Pre-requisites: stopp Windows Time Service habe + disabled it that it is not started by domain...
  9. How do I set up a trusted device PC?

    in AntiVirus, Firewalls and System Security
    How do I set up a trusted device PC?: How do I set up a trusted device in the Windows Security Settings? https://answers.microsoft.com/en-us/windows/forum/all/how-do-i-set-up-a-trusted-device-pc/cbe01e0e-157b-474c-9b00-b30dacd9f4dc"
  10. Microsoft DSRE PKI

    in Windows 10 Network and Sharing
    Microsoft DSRE PKI: Microsoft DSRE PKI Certificate Policy/Certification Practice Statement For TLS CAs (DSRE CP/CPS) is out of date. Should I accept it or will you update your certificate?...