Yubico Forum
https://forum.yubico.com/

YubiKey Certificate (PIV) Enrollment in non-AD environment
https://forum.yubico.com/viewtopic.php?f=30&t=2716
Page 1 of 1

Author:  lil0r [ Fri Sep 22, 2017 5:14 pm ]
Post subject:  YubiKey Certificate (PIV) Enrollment in non-AD environment

Hi all,

I am looking to roll out a large number of YubiKeys in a heterogeneous (a lot of Mac and Linux Client) environment with certificates in PIV mode that is not centrally managed by an AD.
We are looking to deploy a open-source CA such as EJBCA for certificate handling and life-cycle.

We want to enable users to perform sort of a self-enrollment for the certifactes and make this as "simple" as possible to the user. While I understand all the necessary steps using the yubitools such as the pivtool. I am wondering if there is something comparable to the windows based enrollment tools such as the CSIS Enrollment station that works with open-source backends?

Any thoughts or input is greatly appreciated.
Thanks
lIl

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/