Ports required from Client to Windows CA


hi

i am having windows root ca installed on 1 of member server.this server , clients netwrok on different subnet:

for getting client certificates, have opened 135 port client netwrok ca getting error in certificate installation "rpc server unavailable"

after doing research, found certificates works on dcom traffic.does mean open dynamic ports between client netwrok ca network ?

moreover, if need open few dynamic ports 25000-25100 in between, can bind these ports ca server editing registry key ?

if yes, need find other servers dc or number of client getting certificate ca server.

any suggestions please.......

 

regards,

ankur 

remove firewall between clients , ca <g>.

if need through firewall, need restrict ca response single port.

with windows ca, either restrict single port (returned query tcp 135), or have open 1024-65534.

here wiki post kurt hudson describes need do:

http://social.technet.microsoft.com/wiki/contents/articles/how-to-set-a-static-dcom-port-for-ad-cs.aspx?wa=wsignin1.0

brian



Windows Server  >  Security



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...