Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-4112: Does Centrify support certificate enrollment through a static port from the CA?

Centrify DirectControl ,   Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:18 AM

Applies to: Centrify DirectControl for all platforms

Question:
 
The Active Directory Certificate Authority server has been configured to use a static DCOM port and the RPC disabled:
Restricting the ports in this way allows the CA to be placed behind a firewall with tighter controls over which ports are used.
 
Does Centrify support certificate enrollment over a static port?


Answer:
 
Centrify does not currently support CAs on a static-port configuration.

This is because on Windows systems; auto-enrollment is done under the Windows Client Certificate Enrollment Protocol (MS-WCCE), while Centrify systems use the ICertPassage Remote Protocol (MS-ICPR). 
 
Both protocols are based on the MS-RPCE protocol:
Unfortunately since the MS-ICPR protocol has no DCOM implementation, it cannot map a static port for applications to work through. 


See also:


An enhancement request (RFE) has been filed to provide support for this ability in a future release.

(All external links provided as a courtesy)

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.