11/11/2008

System Center Mobile Device Manager (MDM) works directly with your existing Public Key Infrastructure (PKI) for client and server certificate signing. If no current PKI is in place, or if you want to maintain a separate certification authority for device authentication, you can add a Microsoft enterprise certification authority. The Windows Server® 2003 Enterprise Edition operating system certification authority is the only supported issuing certification authority for MDM.

MDM uses certificates for remote authentication of Windows Mobile devices.

Certificate use with MDM provides the following benefits:

Public Key Infrastructure

A PKI consists of the following basic components:

  • Digital certificates

  • Certification Authorities

  • Certificate policy and practice statements

  • Certificate repositories

  • Certificate revocation lists (CRL)

  • Certificate trust lists (CTL)

  • Key archival and recovery

  • Public key standards

For information about PKI, see the PKI documentation:

Certificates

MDM uses certificates from your existing Public Key Infrastructure (PKI).

Windows Server 2003 Enterprise Edition certification authority is the only fully supported certification authority for MDM. Its automatic enrollment and certificate renewal capabilities are key elements in making sure of the highest quality end-user experience during MDM enrollment.

Note:
When you introduce a Windows Server 2003 Enterprise Edition certification authority into a production environment, server certificates are issued to domain controllers.

MDM supports only one root. You must put one Enterprise Root certification authority in the root of the PKI infrastructure.

We recommend that you deploy at least one offline root certification authority and one subordinate (issuing) certification authority. Depending on your deployment, this might include one or more of the following:

  • Active Directory® Directory Service (Windows Server 2003 forest and domain functional levels)

  • Microsoft Domain Name System (DNS), correctly deployed and configured

  • Certification Authority running Windows Server 2003 enterprise edition

  • At least one Global Catalog server in the same Active Directory site as the MDM servers.

  • Microsoft SQL Server® 2005 with Service Pack 1 (SP1), local or remote to the MDM Device Management Server

MDM Certificate Templates

The following certificate templates create during MDM installation. You can view these templates in the Certificate Templates MMC snap-in.

For more detailed information about these templates, see Creating Manual Certificatesin the MDM Deployment Guide.

SCMDM2008GCM

MDM uses the SCMDM2008GCM template for digital signature and encryption.

The following shows information about this template.

Extensions

Client authentication

Validity

Two years

Automatic renewal?

No

Publish to Active Directory?

No

SCMDM2008MobileDevice

MDM uses the SCMDM2008MobileDevice template for digital signature and encryption.

The following shows information about this template.

Extensions

Client authentication

Validity

One year

Automatic renewal?

Yes

Publish to Active Directory?

Yes

SCMDM2008WebServer

MDM uses the SCMDM2008WebServer template for digital signature and encryption.

The following shows information about this template.

Extensions

Server authentication

Validity

Two years

Automatic renewal?

No

Publish to Active Directory?

No

Additional Resources

Windows Server 2003 PKI information

Security and Windows Mobile powered Devices