Home > Intel Communities > Open Port IT Community > Intel® vPro™ Expert Center > Activation > Documents
Currently Being Moderated

Request & Install Verisign Certificate for any ISV

VERSION 1

Created on: Oct 22, 2008 12:10 PM by Sunny Arogunmati - Last Modified:  Oct 22, 2008 12:13 PM by Sunny Arogunmati

Detail description of how to order and install the correct VeriSign certificate for AMT provisioning

Average User Rating
(0 ratings)




arpita bhadra arpita bhadra  says:

In the document, it is mentioned that while generating CSR the Organisational Unit is "Intel(R) Client Setup Certificate".Is the data supplied in the field is irrespective of our setup.What does this field signify and how does it impact our certificate?

 

Moreover,from which server are we supposed to generate the CSR, the server where we intend to install the certificate or the server in which our domain is hosted.

 

Please help.

Terry Cutler Terry Cutler  says in response to arpita bhadra:

There are a few documents and resources posted regarding remote certificates. For an overview, the following may be of interest - http://communities.intel.com/docs/DOC-1490

 

The process noted in Sunny's document above uses Microsoft IIS to generate the CSR and so forth. OpenSSL methods are also supported, thus allowing the certificate request to be handled outside a Microsoft IIS server. However, since Intel SCS requires Microsoft IIS, many have chosen to keep the setup as simple as possible. Similarly - the request can be made on a system that is not the final destination of the certificate - the key is that the certificate request must be authorized by the certificate authority (i.e. VeriSign), meaning that in addition to the CSR, you'll likely need to provide business ownership or domain ownership documentation for an audit trail and so forth.

 

The define OU must be used - this is for remote configuration authentication purposes. Key items must match up between the provisionserver and the Intel AMT client

  • Root certificate hash match
  • OU match is preferred; in some solutions (SMS not included), the certificate OID must be correct
  • DNS suffix match (client's DHCP option 15 to certificate's DNS suffix in canonical name)

 

If you obtain a remote configuration certificate can it be used on more than one server? Yes. Thus it is important that you secure the certificate issued to you. As a comparison - anyone can use the keys to your home or car, the important part is controlling who has access to those keys.

Actions

More Like This

  • Retrieving data ...