<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=30&amp;t=2716" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-09-22T17:14:32+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=30&amp;t=2716</id>
<entry>
<author><name><![CDATA[lil0r]]></name></author>
<updated>2017-09-22T17:14:32+01:00</updated>
<published>2017-09-22T17:14:32+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2716&amp;p=9765#p9765</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2716&amp;p=9765#p9765"/>
<title type="html"><![CDATA[YubiKey Certificate (PIV) Enrollment in non-AD environment]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2716&amp;p=9765#p9765"><![CDATA[
Hi all,<br /><br />I am looking to roll out a large number of YubiKeys in a heterogeneous (a lot of Mac and Linux Client) environment with certificates in PIV mode that is not centrally managed by an AD.<br />We are looking to deploy a open-source CA such as EJBCA for certificate handling and life-cycle.<br /><br />We want to enable users to perform sort of a self-enrollment for the certifactes and make this as &quot;simple&quot; as possible to the user. While I understand all the necessary steps using the yubitools such as the pivtool. I am wondering if there is something comparable to the windows based enrollment tools such as the CSIS Enrollment station that works with open-source backends?<br /><br />Any thoughts or input is greatly appreciated. <br />Thanks<br />lIl<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4905">lil0r</a> — Fri Sep 22, 2017 5:14 pm</p><hr />
]]></content>
</entry>
</feed>