Configuring the NDES server

Configuring the NDES server

  1. From the server, log in as an
    SCEPAdmin
    domain user.
  2. From Server Manager, click
    Manage
    Add Roles and Feature
    .
  3. Click
    Server Roles
    , select
    Active Directory Certificate Services
    and all its features, and then click
    Next
    .
  4. From the AD CS Role Services section, clear
    Certification Authority
    .
  5. Select
    Network Device Enrollment Service
    and all its features, and then click
    Next
    .
  6. From the Web Server Role (IIS) Role Services section, retain the default settings.
  7. After installation, click
    Configure Active Directory Certificate Services on the destination server
    .
  8. From the Role Services section, select
    Network Device Enrollment Service
    , and then click
    Next
    .
  9. Select the
    SCEPSvc
    service account.
  10. From the CA for NDES section, select either
    CA name
    or
    Computer name
    , and then click
    Next
    .
  11. From the RA Information section, specify the information, and then click
    Next
    .
  12. From the Cryptography for NDES section, do the following:
    • Select the appropriate signature and encryption key providers.
    • From the Key length menu, select the same key length as the CA server.
  13. Click
    Next
    .
  14. Complete the installation.
You can now access the NDES server from a web browser as an SCEPSvc user. From the NDES server, you can view the CA certificate thumbprint, the enrollment challenge password, and the validity period of the challenge password.
Accessing the NDES server
Open a web browser, and then type
http://
NDESserverIP
/certsrv/mscep_admin
, where
NDESserverIP
is the IP address of the NDES server.