Centrify DirectControl for all platformsQuestion:
The Active Directory Certificate Authority server has been configured to use a static DCOM port and the RPC disabled:
Restricting the ports in this way allows the CA to be placed behind a firewall with tighter controls over which ports are used.
Does Centrify support certificate enrollment over a static port?
Centrify does not currently support CAs on a static-port configuration.
This is because on Windows systems; auto-enrollment is done under the Windows Client Certificate Enrollment Protocol (MS-WCCE), while Centrify systems use the ICertPassage Remote Protocol (MS-ICPR).
Both protocols are based on the MS-RPCE protocol:
Unfortunately since the MS-ICPR protocol has no DCOM implementation, it cannot map a static port for applications to work through.
An enhancement request (RFE) has been filed to provide support for this ability in a future release.
(All external links provided as a courtesy)