Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Join Domain - request AD computer cert - no MAC Server!

Hello,

I was able to join MAC Lion systems to the domain using the .mobileconfig file and now that I have upgraded to Mountain Lion I am trying to find the proper way to join these systems. It looks like there is a nice easy method, but that appears to require Mountain Lion server.


Does anyone know how ot request a cert for a Mountain Lion system from a MS CA for a domain certificate?


The article I found only seems to Mountain Lion server: http://support.apple.com/kb/HT5357


I don't see any profile/payload manager on the Mountain Lion macbook pro, so is this doc only good for servers?

MacBook Pro with Retina display, OS X Mountain Lion (10.8.1), Active Directory Microsoft CA

Posted on Aug 30, 2012 10:59 PM

Reply
4 replies

Jul 24, 2013 12:54 PM in response to dalehoughton

Apple has a page with some white papers which may be helpful here:


http://training.apple.com/osx


In particular, the best practices for integrating with AD (which references the Kbase you linked to):


http://training.apple.com/pdf/wp_integrating_active_directory_ml.pdf


And the 802.1X authentication white paper:


http://training.apple.com/pdf/WP_8021X_Authentication.pdf


Which includes sample profiles for integrating 802.1X with an AD CA.

Aug 20, 2013 12:12 PM in response to virtually warped

Here is what I found helpful:


802.1x EAP-TLS Machine Authentication in Mt. Lion with AD Certificates

http://www.afp548.com/2012/11/20/802-1x-eaptls-machine-auth-mtlion-adcerts/


How to request a certificate from a Microsoft Certificate Authority using DCE/RPC and the Active Directory Certificate profile payload:

http://support.apple.com/kb/HT5357


I tripped up here becase my CA was named differently than the computer name. If you open a command prompt on the windows CA and type the command certutil –cainfoyou should see several peices of information that will make filling out The name of the CA straight forward. You should use the Sanitized CA short name (DS name) for The name of the CA:

User uploaded file

and certutil –cainfowill clearly show you that value.

One other thing to pay close attension to is you should use the Template name and not the Template display name for the Certificate Template field. These can be different (see below).


User uploaded file


Good luck!

Join Domain - request AD computer cert - no MAC Server!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.