Advanced Autoenrollment Options
Now let's look at some of the advanced autoenrollment options, such as the requirement for certificate manager approval, the selfRA feature, the concept of superseding certificate templates, and the meaning of the Do not automatically reenroll if a duplicate certificate exists in Active Directory certificate template property. These options are available only on Version 2 certificate templates.
Version 2 certificate templates have a property called CA certificate manager approval on the Issuance Requirements tab, as Figure 4 shows. If you set this property, CA manager approval is required before the CA will issue the certificate. Until the CA manager approves the request, it adds the request to the CA's pending request store. The autoenrollment process then periodically checks the CA for approved requests and automatically installs the certificates on the client machine. The CA manager can approve pending certificate requests from the pending request container in the CA snap-in. . . .
Why?
bryces June 26, 2005 (Article Rating: