On your AD Controller or on a separate member server and not the OCS server install the Windows Certificate Authority role from Add/Remove WIndows Programs. I recommend that the Windows OS be enterprise version as an enterprise certificate authority automatically support client and server root certficate autoenrollment setup.
You'll also need IIS on the certificate authority and select Web Enrollment also.
Once you have the certificate authority up and running you can then use the OCS Certificate Wizard to request and assign your OCS Pool certificate and then also update IIS on the OCS box to use that new certificate for the Pool.
For more information on deploying certificates download the document for OCS 207 R2 Deploying Certificates from the OCS documentation download link http://www.microsoft.com/d





by: epaschalPosted on 2009-10-18 at 18:17:36ID: 25602173
I suppose I should mention, if it helps, that the AD controller is a Server 2003 machine.