S
S
Sergey2015-03-03 09:27:26
Active Directory
Sergey, 2015-03-03 09:27:26

What are the options in a network with AD to deploy certificates for various reporting programs?

Sbis and other filth ask for each of their certificates at the workplace. How to implement a shared storage and distribute it to specific accounts? What are the ways?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
N
Nikolai Korabelnikov, 2015-03-03
@nmk2002

Install a full PKI. It is convenient to use smart cards (usb tokens are more common in Russia) to generate a key pair and store it together with a certificate. To manage these smart cards, you need a CMS - Card Management System.
Delivery can be independent. For example, after logging in to the self-service portal using a domain login-password, a user automatically receives all the necessary certificates on a smart card.
After that, CMS independently monitors the need to renew certificates and reminds the user about it.
I implemented such issuance of certificates on OpenTrust PKI + OpenTrust CMS.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question