Seeking Alternative for ADCS Auto-Enrollment with Dogtag-PKI #4986
Unanswered
LH-Lawliet
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
We are in the process of replacing all Microsoft solutions in our infrastructure with open-source alternatives while continuing to use Windows clients. Our teams are accustomed to administering Microsoft interfaces, so we aim to maintain a similar level of usability.
So far, we have successfully replaced Active Directory DC with Samba-DC and are now working on replacing ADCS with Dogtag-PKI, which seems to be the most suitable option. We are comfortable using profiles instead of templates, but we require an auto-enrollment feature. Currently, with ADCS, this is straightforward to configure. However, with Dogtag, it appears that the Auto-Enrollment Proxy (AEP) feature has been deprecated (AEP Documentation).
We would prefer not to use FreeIPA, as this would require managing two separate directories. While we are experimenting with SCEP certificates as an alternative, this approach is not ideal. Additionally, we need a way to specify which profiles an end device can use for auto-enrollment.
Given this situation:
Thank you for your insights!
Beta Was this translation helpful? Give feedback.
All reactions