Create a bunch of computer based certificates

Hi all,
Is there a way to request certificates in where i can choose the subject name of the certificate?
Lets say i want 100 certificates for Ipads, so Ipads can make VPN connection. 
Is it possible to request a certificate and i choose the subject name, for example Ipad1. For the next Ipad i choose Ipad2 as name, so all certificates get a unique name.
Thanks.

Do you want to revoke user certificate automatically when the corresponding user has been deleted?
This has to be done by another custom solution. I had also built such scripts that (e.g.) search for deleted users every night and then revoke the related certificates - but the caveat is that you might end up trying to developing a certificate management
solution here (as Certificate Management in FIM) - considering all processes it gets quite complicated quickly.
There are also third-party solutions for auto-revoking certificates, e.g. the Swiss company keyon has built a so-called
Auto-Revocation Service.
I would probably try to define the requirements in detail and then check if there isn't an existing solution that can cover all this. As for revocation you also should estimate the expected number of revocations per time and related growth of the CRL. Some
VPN solutions have a CRL size limit, I recall 256kB for some (older?) CISCO devices. So especially if you use certificates for devices and VPN make sure the CRL does not become too large (e.g. by renewing the CA with a new key in due time).
As for the mapping: I am not sure of this is really answering your question but for logon purposes (IIS, Smartcard logon, RADIUS....) a user cert. with a UPN gets mapped anyway to an object in AD that has the corresponding UPN attribute, same for machines
and SAN DNS names versus dnsHostName in AD.
Any "accounting" you would want to use AD for, by publishing the certificate to the attribute userCertificate (which is not needed for logon), is something you need develop yourself or add by using another solution.
Elke

Similar Messages

  • How to get a computer based certificate on ipad

    Hi all,
    As the search function keeps loading i will ask here.
    I need a way to get computer based certificates on ipads in order to grant the ipad a VPN connection.
    I already got  it working with a computer based certificate of a laptop, but of course i need certificates that are bound to the ipad.
    Maybe this is more Microsoft related, but is there a way for a user to obtain a certificate from <URL of PKI>/certsrv that automatically assigns a unique (host)name to the certificate? Or is it possible to open that website on the Ipad and obtain a certificate from there?
    i saw an article (http://mobilitydojo.net/2012/01/31/certsrv-vs-mobile-devices/) where they had to do alot of tweaking to get the site working. That is not what we want. But maybe its working on the current version of the Ipad?
    Thanks!

    Well, it's been over two years since I wrote that article and it was obviously on an older version of iOS. So, I decided to take a new stab at it.
    Unfortunately it seems it's still not supported on iOS to use the keygen tag. (It is an HTML5 tag so it's nothing "special" in that sense.
    The "hacks" performed to do this are slightly hackish, that's true, and that is a Microsoft thing There are however other approaches you can take for interfacing with certsrv as well, so if modifying the original certsrv isn't your style you can code up something that will do the request for you (an intelligent proxy if you will). But as long as iOS doesn't play along it doesn't really help.
    The weird thing is that the docs state that it's been supported since iOS 1.0, but I can't find anyone who has gotten it to work. Typo in docs, or bug?
    I don't know if you're using MDM, or you would be ok with deploying through iPhone Configuration Utility, but have you considered if SCEP is an option for getting certs to the devices?

  • 802.1x computer-based network authentication (machine certificate)

    Hello,
    I am using my MBP for work and want to connected to my work's network.
    We are using 802.1x network authentication, based on a computer certificate. I joined my computer to our Microsoft Active Directory and created a computer certificate, which I imported successfully to "System" store.
    Only "Error description" is, that my MBP tries to authenticate as "User".
    How do I configure my network settings, to use "computer-based authentication" and use the computer certificate?
    Regards,
    Ben

    Thanks, but in my case there is no administrator who send me that configuration profile. I have to create a configuration profile for myself.
    I could create a configuration profile for my client and basically it uses a computer certificate to authenticate with the network. But finally the process is cancelled by the client. I tried the steps at OS X Server: How To Configure RADIUS Server Trust in Configuration Profiles when using TLS, TTLS, or PEAP - Apple Suppor… but finally the authentication was cancelled by client, with error ".. server certificate not trusted"
    How should the computer certificate look like?
    Is there a manual for the CA template?
    Regards,
    Ben

  • Registry startup script for computer-based proxy configuration

    I am attempting to deploy computer-based proxy server settings via importing a .reg file to user PCs as a startup script. It has appeared to work on some PCs but not on others. We have a mix of Windows XP Professional x86 and Windows 7 Professional x64 PCs
    in our domain.
    I am not sure whether to use "reg import" or "regedit /s" in my batch script.
    Before trying the batch script method, using "Computer Configuration > Preferences > Registry" settings did not work.
    I have created a GPO, applied it to an OU containing computers and used the following settings:
    Computer Configuration > Policies > Windows Settings > Scripts > Startup
    Batch Script: regedit /s \\FQDN\netlogon\wmproxy.reg
    Registry File:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=dword:00000001
    "MigrateProxy"=dword:00000001
    "ProxyOverride"="<local>"
    "ProxyServer"="proxy.FQDN:8080"
    Computer Configuration > Administrative Templates > Windows Components/Internet Explorer
    Disable changing proxy settings = Enabled
    Make proxy settings per-machine (rather than per-user) = Enabled
    As at the beginning of my post, the settings deploy to some PCs but not all and I have yet to see it work on the Windows 7 PCs. Am I attempting computer-based proxy settings the wrong way, or am I missing something with how I am currently trying to deploy
    it?
    Thanks all!

    Hi,
    You mentioned you have tried to configure the computer-based proxy settings via GPP but it didn’t work. Before going further, would you please let me know how did you configure the settings?
    In order to narrow down the cause of the issue, I suggest we’d better collect the following information.
    GPMC.log
    ==================
    a. On domain controller, click Start ->Run, type GPMC.MSC, it will load the GPMC console.
    b. Right click on "Group Policy Result" and choose wizard to generate a report for the problematic computer and user account (please place appropriately). (Choose computer and select the proper
    user in the wizard)
    c. Right click 
    the resulting group policy result and click the "Save Report…" => save report to save the report to a HTML file.
    Once we get the GPMC.log, please check the detailed report logged in it.
    You said you have created a startup script to edit the registry key to configure the proxy setting of the computer but it worked on only some of the computers in the domain. Have you tried
    to run the script on the problematic computer manually to see if it works? If it still fails to run, it could be related to the script issue, then we’d better ask in the script forum.
    The Official Scripting Guys Forum!
    http://social.technet.microsoft.com/Forums/en-US/ITCG/threads
    Regards,
    Andy

  • Can't get internet access to computer based DVR

    I have a computer based DVR  (security cameras), that I want to be able to see through the internet. I have done a lot of reading on the net for how to set port forwarding in both the router (Linksys  WRT54G) and the modem (Westell 6100G). I can access the camera computer from other computers on the LAN using the camera computer local IP or by using the router IP, but can’t get to the camera computer from the internet. The modem is bridged  and I created a port forward to the camera computer both in the modem and router. What am I missing?

    I apologize I didn't realize it was a linksys router
    http://www.portforward.com/english/routers/port_forwarding/Linksys/WRT54Gv2.04/DINA_DVR_Server.htm
    This is a similiar set up and linksys requires that you put a port number for the start. 
    it looks like it wants the same number as the end
    so 9000 start  and 9000 end
    take a look at that site, and tell me if that helps.   sorry about that.

  • Create A/R credit memo based on paid (closed) A/R invoice.

    Hello All,
    Many customers need a possibility to create credit memo based on paid invoice to make control on sales quantities, sales price with any discount and cost of good sold.
    Is there a way to create A/R credit memo based on closed A/R invoice (Paid) in B1 ?
    Best Regards,
    Khaleel Abu Dayyeh

    Hi Khaleel,
    You have to Cancel Incoming Payment to Open AR Invoice.
    Then pass AR Credit Memo for that Invoice which was Closed after Creation Incoming Payment on behalf of this Invoice.
    So Cancel Incoming Payment and Open AR Invoice and Create Credit Memo on Behalf of Invoice.
    There is no other work around for this Scenario
    Hope this helps
    Regards::::
    Atul Chakraborty

  • How can I create an IList Employee list based on my Employee class?

    I'm trying to create an IList<Employee> list based on my Employee class (below).  But this is erroring out.  Is my employee class missing anything?  How could I make this work?
    private void EmployeeList()
    IList<Employee> arL = new IList<Employee>(); //<<<<----errors out here
    arL.Add(new Employee {Name="Mary",Gender="Female", Age=35});
    arL.Add(new Employee { Name = "Bob", Gender = "Male", Age = 40 });
    arL.Add(new Employee { Name = "Tom", Gender = "Male", Age = 50 });
    var qm = from Employee employee in arL
    where employee.Age < 50
    select employee;
    foreach (var m in arL)
    Console.WriteLine(m.ToString());
    class Employee
    private string name;
    private string gender;
    private int age;
    public string Name
    get { return name; }
    set { name = value; }
    public string Gender
    get { return gender; }
    set { gender = value; }
    public int Age
    get {return age;}
    set {age = value;}
    Rich P

    IList is an interface, not a class. This means that it can't be instantiated (can't be "newed").
    List is a class, so it can be instantiated. It implements the IList interface, which means that it must provide the functionality specified in that interface.
    That's what an interface is - a definition of functionality that a class must provide. An interface is often described as a contract that a class must fulfill.
    So in the code in your last post, you are saying that arL is an instance of some class that implements the IList interface, and you are then setting it to an instance of the class List. The List class implements the IList interface, so this assignment is
    legit. It would also be legit to use any other class that implements IList, such as an array.
    Any class that implements IList can have as much extra functionality as whoever wrote it likes, as long as it implements at least the functionality of the interface.
    Sometimes you will come across a method in a library over which you have no control and which returns IList rather than list. In such a case you will be forced to do something like...
    IList list = SomeMethodOrOther();
    So you will have no idea what class list is an instance of, but you will know that it has the functionality of IList. This is about the only circumstance where I would recommend defining a variable as IList rather than List (but it probably won't be long
    before there are some replies to this post that disagree).

  • I cannot open my document in pages 5.0.1 that I created in same. Computer tells me that I need to have a later version of pages. What do I do?

    i cannot open my document in pages 5.0.1 that I created in same. Computer tells me that I need to have a later version of pages. What do I do?

    You're running an older version of Pages, perhaps in a folder called "iWork '09" in the Applications folder, or else on your Desktop. Quit it and launch the one at the top level of Applications.

  • Creating a Form with Report based on View

    Hi All,
    I wanted to create a form with report based on two tables so:
    1. I created a view (called COMBO) based on two tables
    2. I then created a form with report based on the view
    Everything seemed fine thus far until I tried to edit existing records - I got the error:
    ORA-20505: Error in DML: p_rowid=2002082600001172, p_alt_rowid=REPATRIATION_ID, p_rowid2=, p_alt_rowid2=. ORA-01776: cannot modify more than one base table through a join view
    Unable to process row of table COMBO.NB: REPATRIATION_ID is the primary key of the Repatriation table. The other table is Applicant.
    & when I tried to create a new record - I got the error:
    ORA-01776: cannot modify more than one base table through a join view
    Unable to process row of table COMBO.Someone please enlighten me!
    Kind Regards
    Kamo
    Edited by: Kamo on 2009/03/12 2:33 AM

    Hello Kamo,
    You need to create an 'instead of' (update/insert/delete) trigger on your view to process the inserts etc into the 'real' tables.
    Greetings,
    Roel
    http://roelhartman.blogspot.com/
    You can reward this reply by marking it as either Helpful or Correct ;-)

  • How to create dynamic ed flash charts based on user selected fields in Orac

    Hi all,
    Can any of the experts please tellme "how to create dynamic ed flash charts based on user selected fields in Oracle apex".
    Thanks
    Manish

    Hello,
    Lots of different ways to do this, I blogged about one way (using a Pipelined function) here -
    http://jes.blogs.shellprompt.net/2006/05/25/generic-charting-in-application-express/
    Other options include using a PL/SQL function returning the string to use as the dynamic query etc.
    Hope this helps,
    John.
    Blog: http://jes.blogs.shellprompt.net
    Work: http://www.apex-evangelists.com
    Author of Pro Application Express: http://tinyurl.com/3gu7cd
    REWARDS: Please remember to mark helpful or correct posts on the forum, not just for my answers but for everyone!

  • Creating a Dynamic Update Statement based on Select

    hi,
    i'm trying to create a dynamic update statement based on select statement
    my requirment is to query a joint tables and get the results then based on the results i need to copy all the data and create an update statement for each row
    for ex
    the update statement should look like this
    update iadvyy set SO_SWEEP_CNT = '1' where inst_no = '003' and memb_cust_no = 'aaaaaaaaaaaaaaaa';
    and the select statement like the following
    select substr(key_1,11,9) account_no,sord_mast SO_SWEEP_CNT from
    select acct_no,count(*) sord_mast from
    (select from_acct_no acct_no,update_mast
    from sord where FROM_SYS in ('DEP','INV') and TERM_DATE > 40460
    union all
    select to_acct_no acct_no,update_mast
    from sord where TO_SYS in ('DEP','INV') and TERM_DATE > 40460)
    group by Acct_no)
    right outer join
    invm
    on
    key_1 = '003'||acct_no
    where sord_mast > 0;
    so taking the above two columns from the above select statement and substitue the values as separate update statement.
    is that doable , please share your knowledge with me if poosible
    thanks in advanced

    is that doable , please share your knowledge with me if poosibleyes
    The standard advice when (ab)using EXECUTE IMMEDIATE is to compose the SQL statement in a single VARCHAR2 variable
    Then print the SQL before passing it to EXECUTE IMMEDIATE.
    COPY the statement & PASTE into sqlplus to validate its correctness.

  • How to create a service entry sheet based from the PO

    how to create a service entry sheet based from the PO
    Gurus,
    I am creating a service entry sheet from the PO but I am getting an error of u201CPlease maintain services or limits Message no. SE029- Diagnosis(You cannot enter data until the PO item has been maintained correctly) u201C
    The document type of the PO is standard NB, account assignment category is Q- (Proj make to order) and the item category is D(service). Then I am trying also create a PR using account assignment category is Q- (Proj make to order) and the item category is D(service) but still cannot proceed, a message asking me to enter a service entry number. What I know the process is create a PO(maybe based from PR) then post the GR then create a service entry sheet in ML81N but I cannot proceed. Just creating a PR or PO using those mentioned account assignment and item category and getting an error of need to enter a service entry sheet number.
    Please help.thanks!

    HI,
    Process for Creating Service Entry Sheet
    Transaction Code :    ML81N
    1)To open the respective Purchase Order, Click on the u2018Other Purchase Orderu2019, then enter the Purchase Order No.
    2)Click on the u2018Create Entry Sheetu2019 icon(3rd Icon on Top-Left)
    3)Give Short Text (e.g. R/A Bill No. 1) and top service entry sheet number also generated.
    4)Click u2018Service Selectionu2019 Icon on the Bottom of the Screen.
    5)For the 1st Time, when we are making Service Entry Sheet for a respective Purchase Order, we need to u201CAdopt Full Quantityu201D by clicking the Check box next to it, then Enter.  (*For the next time, no adoption is required, just continue)
    6)Select the respective Services by clicking on the Left Hand Side, then Click u2018Servicesu2019 (Adopt services) icon on the Top.
    7)Give the completed Quantity, then Click u2018Acceptu2019 icon(a green flag on the top)
    8)Save .
    9)Service Entry Sheet is SAVED and account posting made.
    Hope, it is useful for you,
    Regards,
    K.Rajendran

  • Can the license manager load the computer-based license first, instead of the user-based license?

    We have several machines in the lab with computer-based licenses on them and a number of techs with user-based licenses. When a tech needs to occassionally sign in as themselves, instead of the generic service account, the license manager attaches the machine to their user account. Not a problem until they try logging in to LabVIEW from their own PC again and they get the 14 day trial period notice.
    Is there a way to have the license manager look for the computer license first instead of the user license?
    Thanks for any help.
    Joe
    Solved!
    Go to Solution.

    Hi Joe,
    In the license file hosted on the license server, you may be able to manually change the "sort" tag in the file to modify the order in which VLM checks out licenses. Licenses are checked out in descending order (2, then 3, then 4, etc.). Typically, your license file is set up in a default order, but in special cases such as this, it may be beneficial to alter the order. To do this, follow these steps:
    1. Open the license file with a text editor (such as Notepad)
    2. Search for the "sort" tag. For instance, the "VLM_Core" entry will have a sort tag value will appear as "sort=first". Do not alter this value. VLM_Core should always be first.
    3. Change the sort tag value for the named-computer license to a value that is lower than the sort tag value for the named-user license. (e.g. "sort=2" for named-computer and "sort=3" for named-user). 
    4. Save the file and reinstall the license. 
    Let me know if you have any questions!
    Rick C.

  • Do I have to use computer based mail app to send mail through Safari?

    Can't believe I am confused on this...but....if I click on an email link in a web page that I am looking at in Safari, does sending email require opening and sending through a separate computer based mail app? My email accounts are through AOL, but doesn't seem that even if I sign in at AOL's website, that I can access a web page through them, and in turn have mail links link to my online AOL email page. That means that I have to use a mail app that people who access my computer and open and look into?

    Hi Jim,
    You can set up AOL mail using the Mac Mail application, instructions here.
    http://macs.about.com/od/applications/qt/mailaol.htm
    That means that I have to use a mail app that people who access my computer and open and look into?
    Only if you share your login user name and password with them.
    If you allow visitors to use your Mac, you can setup a guest account for them to use.
    http://docs.info.apple.com/article.html?path=Mac/10.5/en/15600.html
    The instructions at that link are for v10.5 but it works fine for v10.6 as well.
    Carolyn

  • Cannot create JAVA on new computer...please help

    I have not been able to actually view anything I create with Java on my new computer. I have tried installing the latest update of Java but it didn't help. Sun Java was already installed on this computer.
    I use Front Page to create web sites and have never had a problem before.
    When I create a Java effect, I can see the Java Icon in normal view but as soon as I try to preview... nothing shows up.
    The Java effects i created on my other computer show up on this computer...
    please help ...

    Thank you for your response but this doesn't help.This is a forum for Programming in Java. Your question appears to be targeted at something else, Digital Video maybe? Possibly Applets? We don't know, and you aren't giving enough information to make a decent guess. If you have a Java code development-related question this would be the place to post that.
    Perhaps you want a Microsoft Forum?
    Good Luck
    Lee

Maybe you are looking for

  • My clock is possessed

    My clock won't display in the upper right corner on the desktop. It just blinks on and off, along with the volume, wireless and bluetooth symbols. When I go to system preferences and select "show date and time in menu bar" it deselects on it's own an

  • AS3 Timer Function Help

    Hi, I am trying to create a desktop countdown timer (personal project) however I am getting some issues with the script.  The countdown timer works fine until I try and get user inputs.  I have created some variables  to store the end date and have a

  • I want to remove greasemonkey add-on. How do I do that?

    I want to remove greeasemonkey add0on

  • Sending serialization data via intranet.

    This is what I have: SMS Messaging server, there running my own program handling the SMS messages. The message handling routines will be handled with programminglanguage I have designed. It will compile the statements into java Object structure. The

  • Nokia 6288 Memory Card Formatted

    I have accidentally formatted my memory card and lost all the data. I have bought my phone in Dubai and I am now in Manila. Can anyone help me how to have the same data by sending me a link or zip file of it? Thanks!