Computer and User Certificate Auto Enrollment over SSL VPN connection

ssaini 1 Reputation point
2021-06-18T10:18:39.45+00:00

We are using Microsoft PKI to issue user and computer certificates using autoenrollment to window 10 machines. Certificates are issuing perfectly for machines connected on corporate LAN using wired and wireless connectivity. But certificate not getting issued for window 10 endpoints connected on SSL VPN ( working from home). Autoenrollment GPO is linked to endpoints and applied successfully over VPN connection, also endpoints have autoenroll rights on template.

VPN gateway is setup in a way that we need to reconnect VPN once signout and signin back into the computer.

No event has been seen in event viewer for updating local certificate store for any newly issued certificate and MMC personal store is showing blank. Please suggest how to autoenroll certificates for window 10 machines connected on SSL VPN connection.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
3,044 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Vicky Wang 2,736 Reputation points
    2021-06-21T09:53:22.713+00:00

    Step 1 - Create a security group
    To create a security group on Active Directory

    On DC1, click Start > Administrative Tools, and then click Server Manager.
    In the navigation pane, expand Roles, expand Active Directory Domain Services, expand Active Directory Users and Computers, expand contoso.com, right-click Users, click New, and then click Group.
    In the New Object - Group dialog box, in the Group name text box, type a name for the group. Example: AutoEnrollGroup.
    Click OK. Leave Server Manager running with the Computers container shown in the results pane.
    Step 2 - Create a certificate template to enroll
    To create a certificate template

    Open the Certificate Templates Console
    From the Start menu, click Run.
    Type certtmpl.msc in the text box and click OK. Certificate Templates Console window appears on the page.
    Under General tab,
    Type a Template display name. For example, User Auto Enroll.
    (Optional) Modify the default Validity Period and Renewal Period as per your requirements.
    Select Publish certificate in Active Directory check box.
    reference:https://docs.druva.com/Knowledge_Base/inSync/How_To/How_to_set_up_automatic_certificate_enrollment_in_Active_Directory

    0 comments No comments

  2. Vicky Wang 2,736 Reputation points
    2021-06-24T07:37:13.863+00:00

    Hi,

    Welcome to share your current situation if there are any updates.

    Please feel free to let us know if you need further assistance.

    Best Regards,
    Vicky

    0 comments No comments

  3. Vicky Wang 2,736 Reputation points
    2021-06-29T09:40:50.47+00:00

    Hi,

    Welcome to share your current situation if there are any updates.

    Please feel free to let us know if you need further assistance.

    Best Regards,
    Vicky

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.