单项选择题
You have a server named Server1 that has the following Active Directory Certificate Services (AD CS) role services installed:
-Enterprise root certification authority (CA) -Certificate Enrollment Web Service -Certificate Enrollment Policy Web Service
You create a new certificate template.
External users report that the new template is unavailable when they request a new certificate. You verify that all other templates are available to the external users.
You need to ensure that the external users can request certificates by using the new template.
What should you do on Server1()
A.Run iisreset.exe /restart.
B.Run gpupdate.exe /force.
C.Run certutil.exe -dspublish.
D.Restart the Active Directory Certificate Services service.
相关考题
-
单项选择题
Your network contains two Active Directory forests named contoso.com and adatum.com. The functional level of both forests is Windows Server 2008 R2. Each forest contains one domain. Active Directory Certificate Services (AD CS) is configured in the contoso.com forest to allow users from both forests to automatically enroll user certificates. You need to ensure that all users in the adatum.com forest have a user certificate from the contoso.com certification authority (CA). What should you configure in the adatum.com domain()
A.From the Default Domain Controllers Policy, modify the Enterprise Trust settings.
B.From the Default Domain Controllers Policy, modify the Trusted Publishers settings.
C.From the Default Domain Policy, modify the Certificate Enrollment policy.
D.From the Default Domain Policy, modify the Trusted Root Certification Authority settings. -
单项选择题
Your network contains an Active Directory domain. You have a server named Server1 that runs Windows Server 2008 R2. Server1 is an enterprise root certification authority (CA). You have a client computer named Computer1 that runs Windows 7. You enable automatic certificate enrollment for all client computers that run Windows 7. You need to verify that the Windows 7 client computers can automatically enroll for certificates. Which command should you run on Computer1()
A.certreq.exe -retrieve
B.certreq.exe -submit
C.certutil.exe -getkey
D.certutil.exe -pulse -
单项选择题
YournetworkcontainsanActiveDirectorydomain.Therelevantserversinthedomainareconfiguredasshowninthefollowingtable: ServernameOperatingSystemServerroleServer1Windows2008Domaincontroller Server2Windows2008R2Enterpriserootcertificationauthority(CA) Server3Windows2008R2NetworkDeviceEnrollmentService(NDES) YouneedtoensurethatalldevicecertificaterequestsusetheMD5hashalgorithm. Whatshouldyoudo()
A.On Server2, run the Certutil tool.
B.On Server1, update the CEP Encryption certificate template.
C.On Server1, update the Exchange Enrollment Agent (Offline Request) template.
D.On Server3, set the value of the HKLM\Software\Microsoft\Cryptography\MSCEP\HashAlgorithm\HashAlgorithm re
