Configuring the NDES server
- From the server, log in as anSCEPAdmindomain user.From Server Manager, click .ClickServer Roles, selectActive Directory Certificate Servicesand all its features, and then clickNext.From the AD CS Role Services section, clearCertification Authority.SelectNetwork Device Enrollment Serviceand all its features, and then clickNext.From the Web Server Role (IIS) Role Services section, retain the default settings.After installation, clickConfigure Active Directory Certificate Services on the destination server.From the Role Services section, selectNetwork Device Enrollment Service, and then clickNext.Select theSCEPSvcservice account.From the CA for NDES section, select eitherCA nameorComputer name, and then clickNext.From the RA Information section, specify the information, and then clickNext.From the Cryptography for NDES section, do the following:
- Select the appropriate signature and encryption key providers.
- From the Key length menu, select the same key length as the CA server.
ClickNext.Complete the installation.You can now access the NDES server from a web browser as an SCEPSvc user. From the NDES server, you can view the CA certificate thumbprint, the enrollment challenge password, and the validity period of the challenge password.Accessing the NDES serverOpen a web browser, and then typehttp://, whereNDESserverIP/certsrv/mscep_adminis the IP address of the NDES server.NDESserverIP