Microsoft Intune MDM DigiCert 2018 7 31
Microsoft Intune MDM DigiCert : 2018 7 31 Copyright 2018 DigiCert, Inc. All rights reserved. DigiCert DigiCert DigiCert, Inc. Symantec Norton Symantec Corporation DigiCert, Inc. DigiCert, Inc. FAR 12.212 Commercial Computer Software - Restricted Rights FAR Section 52.227-19 Rights in Commercial Computer Software or Commercial Computer Software Documentation DFARS 227.7202 104-0061 6 10 1 GINZA SIX 8 03-4560-3900 https://www.digicert.co.jp JPN-DIV-MPKI@digicert.com 2
...4...5...6 Intune...7 RA...8 Microsoft Intune Certificate Connector... 10... 12 DigiCert PKI... 12 Intune... 14 Intune... 15... 15... 16 3
Microsoft Intune Office Microsoft Intune DigiCert PKI Platform DigiCert PKI Platform PKI Microsoft Intune DigiCert PKI Platform 8.17.x 1. Microsoft Intune RA 2. Intune DigiCert PKI Platform Microsoft Intune 3. Intune 4. Intune 4
1. 2. RA 3. Microsoft Intune 4. DigiCert PKI 5. Intune 6. Intune 7. 8. 5
DigiCert PKI DigiCert PKI Platform DigiCert PKI Manager Microsoft Intune Microsoft Intune NDES 6
Intune Intune Certificate Connector Microsoft Windows Server 2012 R2 Microsoft Windows Server 2008 R2 Microsoft.NET Framework 3.5 ASP.NET Microsoft Intune 7
RA CSR DigiCert PKI Manager RA PKI RA Intune DigiCert PKI Platform CA RA Intune RA RA RA RA RA https://knowledge.digicert.com/ja/jp/solution/ SO29805.html CSR 1. Intune NDES certreq.inf 2. certreq.inf [NewRequest] Subject = CN=Registration Authority KeySpec = 1 KeyLength = 2048 Exportable = FALSE MachineKeySet = TRUE PrivateKeyArchive = FALSE UserProtected = FALSE UseExistingKeySet = FALSE ProviderName = Microsoft RSA SChannel Cryptographic Provider ProviderType = 12 RequestType = PKCS10 KeyUsage = 0xa0 HashAlgorithm = sha256 ;-------------------------------------- --------- CSR certreq.exe -new certreq.inf racertificate.req racertificate.req CSR CSR DigiCert PKI Manager RA 3. racertificate.req DigiCert PKI Manager 8
DigiCert PKI Manager RA 1. racertificate.req 2. DigiCert PKI Manager RA 3. CSR 4. RA-certificate. p7b 5. RA-certificate.p7b NDES RA RA 1. RA certreq -accept -machine RAcertificate.p7b 2. certutil certutil -store MY RA 9
Microsoft Intune Certificate Connector Intune Certificate Connector RA Intune Certificate Connector Microsoft Intune Intune Certificate Connector RA Intune MPKI RA Intune RA RA 1. certutil -store MY 2. RA 3. Cert Hash 1. NDESConnectorSetup.exe 2. PFX Distribution PFX 4. Cert Hash 91 6c 8d 18 47 0a ad 55 db cf a3 6b 0f 5c fe 61 88 916c8d18470aad55dbcfa36b0f5cfe6188 Cert Hash 10
DigiCert PKI Platform RA 1. %ProgramFiles%\Microsoft Intune\NDESConnectorSvc\NDESConnector.exe. config 2. RACertThumbprint Cert Hash Cert Hash 916c8d18470aad55dbcfa36b0f5cfe6188 3. 4. services.msc 5. Intune Connector Service 6. Intune 1. %ProgramFiles%\Microsoft Intune\ NDESConnectorUI\NDESConnectorUI.exe NDES 2. Enrollment Sign In 3. Intune 4. Sign In Successfully enrolled 5. NDES 11
DigiCert PKI Platform Intune DigiCert PKI Platform Intune OID DigiCert PKI DigiCert PKI Platform 1. DigiCert PKI Platform 2. DigiCert PKI Manager 4. 5. Client Authentication 1. 2. PKI Web 3. Subject DN (CN) firstname lastname 3. Intune Web 1. 12
2. 4. 5. OID OID PKIManagerCertificateProfileOID 3. : CN : Web : 13
Intune DigiCert PKI Manager Intune 1. Intune Device configuration 1. DigiCert PKI Manager CA 2. Name Description 3. 4. Trusted certificate 5. DigiCert PKI Manager OK 2. CA 3. 6. Device Configuration Assignments 14
Intune Intune 1. Intune Device Configuration 2. Settings Configure Profile type PKCS certificate Certificate authority (production) https://pki-ws.symauth.com Certification authority name Symantec Certificate template name PKIManagerCertificateProfileOID DigiCert PKI Manager OID 3. OK 4. Device Configuration Assignments 1. Microsoft Intune Company Portal 2. Intune 3. 15
Microsoft Network Device Enrollment Services NDES Microsoft Intune DigiCert PKI DigiCert PKI pki-ws. symauth.com Intune Microsoft NDES NDES Intune : %ProgramFiles%\Microsoft Intune\ NDESConnectorSvc\Logs\* NDES DigiCert PKI Platform : %ProgramFiles%\Microsoft Intune\ PfxRequest\* 80 443 https 443 Intune https 443 Intune Certificate Connector NDES PFX 2018 DigiCert, Inc. All rights reserved.digicert DigiCert, Inc. 16