The following checklist provides the steps required to deploy the public key infrastructure (PKI) requirements before a Configuration Manager 2007 site can operate in native mode.
Step | Reference | ||
---|---|---|---|
Confirm your PKI can support the various certificates required by Configuration Manager 2007. |
|||
Ensure the following computers in the Configuration Manager 2007 site have a trusted root certification authority in common and intermediate certification authorities as needed:
|
Deploying a Trusted Root Certification Authority to Configuration Manager Computers Deploying the Intermediate Certification Authority Certificates to Configuration Manager Computers |
||
If you will use a Certificate Revocation List (CRL), publish it where all computers can locate it. |
Certificate revocation checking is enabled by default for Configuration Manager clients, but it can be disabled. For more information, see Determine Whether You Need to Enable Certificate Revocation Checking (CRL) On Clients (Native Mode). Certificate revocation checking is enabled by default with IIS and cannot be disabled with Configuration Manager. Ensure that native mode site systems can connect to a CRL distribution point that is listed in their site system certificate.
|
||
Deploy the site server signing certificate to the site server, and determine how clients will retrieve it. |
Deploying the Site Server Signing Certificate to the Site Server Decide How to Deploy the Site Server Signing Certificate to Clients (Native Mode) |
||
Deploy the Web server certificates to the following site systems, and then configure IIS with the certificate:
|
Deploying the Web Server Certificates to Site System Servers |
||
Optional but recommended: On the site systems with the deployed Web server certificates, create or modify a certificate trust list (CTL) in IIS to contain the root certification authorities used by clients. |
Determine If You Need to Configure a Certificate Trust List (CTL) with IIS (Native Mode) |
||
Deploy client certificates to clients and management points. |
Deploying the Client Computer Certificates to Clients and the Management Point |
||
If you have mobile client devices, deploy the client device certificates. |
|||
If you are using the operating system deployment feature, perform the following tasks:
|
How to Prepare the Root Certification Authority Certificates for Operating System Deployment Clients How to Specify the Root Certification Authority Certificates for Operating System Deployment Clients How to Export Certificates For Use With Operating System Deployment |
See Also
Tasks
How to Configure the Site Server with its Site Server Signing CertificateHow to Migrate the Site Mode from Mixed Mode to Native Mode
Concepts
Administrator Checklist: Migrating a Site to Native ModeAdministrator Workflow: Deploying the PKI Requirements for Native Mode
Prerequisites for Native Mode