Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

SOLVED sccm pki configuration and two domain

  • Thread starter Thread starter mriboli
  • Start date Start date
  • Replies Replies 2
  • Views Views 2K

mriboli

New Member
Messages
3
Reaction score
0
Points
1
Hi all,

i have two domains, in the first one i have the database, the site system, distribution point, management point, software update point and so on.
In the other domain that is in DMZ, i have installed this role: site system, management point, distribution point, component server.
All works fine in http configuration, now for enhance the security we have to switch the communication in HTTPS.
In the first domain we have a PKI that actually is not used by SCCM and Clients.
The sysadmin has just installed a PKI in DMZ, so we can use the automatic enroll of the certificate.
I read a lot of page about this argument but I have a big doubt, I ave to export the web server certificate to the server in DMZ or i can generate the certificate for the web server in DMZ without problem?

My step for gain HTTPS communication is:

Generate the client certificate with autoenroll for every domain.
Generate web server certificate for the primary domain and switch the communication from HTTP to HTTPS.
Generate web server certificate for the other domain and switch the communication from HTTP to HTTPS.
Is that right or I'm missing something ?

Best Regards
Massimo Riboli
 
Don't get me wrong, this is a complex scenario and I would suggest hiring a consultant for this work.
 
Back
Top