Mutual Authentication in System Center Essentials 2007

 

I’ve seen the question come up a few times “How do I deploy certificates for mutual authentication in SCE”? And the fact is you cannot. SCE requires that agent-managed computers have membership in a domain.

However, SCE does use certificates, just not for mutual authentication between agent and management server.

There are actually 2 certificates used in SCE, both used by the WSUS component:

· WSUSCodeSigning.cer: This is the code signing certificate that the server uses to sign locally published updates. This certificate must be trusted by client computers in order to install locally published updates.

· WSUSSSL.cer: This is the SSL certificate that is used by the WSUS Administration web site. The certificate must exist in the client’s local computer certificate store in order to connect to the Essentials server to check for updates.

NOTE: System Center Essentials does NOT support using certificates issued by a third-party certificate authority for the SSL and Code Signing certificates.

· The hash for these certificates is stored in the registry under HKLM\Software\ Microsoft\ System Center Essentials\1.0\PolicySettings (SSLCerthash and WSSUCodeSigningCertHash).

· Certificates files should be placed in <EssentialsFolder>\Certificates.

One Response to “Mutual Authentication in System Center Essentials 2007”

  1. System Center Forum - Installing Essentials 2007? Read these first! Says:

    [...] Mutual Authentication in System Center Essentials 2007 [...]

Leave a Reply

privacy policy | terms of use | copyright © 2008 pete zerger