Issuing Enrollment and User Certificates Using ADCS

About this task

Use ADCS and the Microsoft Management Console (MMC) to request and export updated enrollment and authentication certificates for integration with SOTI MobiControl. Use these certificates to enable secure device enrollment and user authentication within the system.

Procedure

  1. Log in to the CA server as the Active Directory Certificate Services (ADCS) user. Alternatively, open the MMC as a different user by holding down the Shift key and right-clicking MMC, then selecting Run as different user.
  2. Launch the MMC and add the Certificates snap-in (User Account).
  3. Right-click Personal and select All Tasks > Request New Certificate. The Certificate Enrollment wizard displays.
  4. Select Next and select the certificate derived from the Enrollment Agent template during the initial setup.
  5. Repeat the above steps to retrieve the Authentication certificate.
  6. Select More information… > Properties > Signature.
  7. Select Browse.
  8. In the Windows Security dialog box that opens, select the Enrollment Certificate generated in Step 4 above.
  9. Export both certificates with their private keys. Name the certificates properly for the SOTI MobiControl configuration. One is the Enrollment certificate, while the other is the Client Authentication User certificate.

What to do next

Import the new certificates into your SOTI MobiControl instance to complete or renew your ADCS integration. For more information, see Step One: Integrate Certificate Authority Services.