<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blogotec, VMWare, Hyper-v, NetApp &#187; certificat</title>
	<atom:link href="http://www.blogotec.fr/tag/certificat/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blogotec.fr</link>
	<description>VMware vSphere, Microsoft Hyper-v, NetApp, SCOM, Virtualisation</description>
	<lastBuildDate>Tue, 07 Feb 2012 13:36:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>SCOM 2007 : Comment déployer un agent en DMZ avec certificat</title>
		<link>http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat</link>
		<comments>http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 20:39:07 +0000</pubDate>
		<dc:creator>Rémy</dc:creator>
				<category><![CDATA[SCOM 2007]]></category>
		<category><![CDATA[2007]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[center]]></category>
		<category><![CDATA[certificat]]></category>
		<category><![CDATA[dmz]]></category>
		<category><![CDATA[installation]]></category>
		<category><![CDATA[manager]]></category>
		<category><![CDATA[ms]]></category>
		<category><![CDATA[operation]]></category>
		<category><![CDATA[pfx]]></category>
		<category><![CDATA[rms]]></category>
		<category><![CDATA[system]]></category>

		<guid isPermaLink="false">http://www.blogotec.fr/?p=321</guid>
		<description><![CDATA[Déploiement d&#8217;un agent en DMZ   how to deploy agent on DMZ/comment deployer un agent en dmz 1. Import du<a href="http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/" class="searchmore">Lire la suite...</a><div class="clr"></div>]]></description>
			<content:encoded><![CDATA[<h1 style="text-align: center;"><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/telecharger-certificat_03.jpg"></a><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/pending-request_11.jpg"></a>Déploiement d&#8217;un agent en DMZ</h1>
<p> </p>
<p><em>how to deploy agent on DMZ/comment deployer un agent en dmz</em></p>
<h2><span style="font-weight: normal;">1</span>. Import du certificat d&#8217;autorité</h2>
<p>Action à réaliser depuis les serveurs en DMZ, RMS et MS</p>
<p>Se connecter au serveur de certificat : <a href="http://certserv.domain.com/cersrv">http://certserv.domain.com/cersrv</a></p>
<ul>
<li>Récupérer le certificat de l&#8217;autorité de certification</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/recuperer-le-certificat-racine_01.jpg"><img class="alignnone size-full wp-image-322" title="recuperer-le-certificat-racine_01" src="http://www.blogotec.fr/wp-content/uploads/2009/03/recuperer-le-certificat-racine_01.jpg" alt="recuperer-le-certificat-racine_01" width="609" height="138" /></a></p>
<ul>
<li>Télécharger le chemin du certificat de l&#8217;autorité de certification</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/telecharger-certificat-racine_02.jpg"><img class="alignnone size-full wp-image-323" title="telecharger-certificat-racine_02" src="http://www.blogotec.fr/wp-content/uploads/2009/03/telecharger-certificat-racine_02.jpg" alt="telecharger-certificat-racine_02" width="445" height="227" /></a></p>
<p> </p>
<ul>
<li>Téléchargement du certificat</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/telecharger-certificat_03.jpg"><img class="alignnone size-full wp-image-324" title="telecharger-certificat_03" src="http://www.blogotec.fr/wp-content/uploads/2009/03/telecharger-certificat_03.jpg" alt="telecharger-certificat_03" width="277" height="185" /></a></p>
<ul>
<li>MMC certificat / Computer Account</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/mmc-computer-account_04.jpg"><img class="alignnone size-full wp-image-325" title="mmc-computer-account_04" src="http://www.blogotec.fr/wp-content/uploads/2009/03/mmc-computer-account_04.jpg" alt="mmc-computer-account_04" width="609" height="328" /></a></p>
<ul>
<li>Import du certificat certnew.p7b</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/import-certificat_05.jpg"><img class="alignnone size-full wp-image-326" title="import-certificat_05" src="http://www.blogotec.fr/wp-content/uploads/2009/03/import-certificat_05.jpg" alt="import-certificat_05" width="565" height="328" /></a></p>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/place-all-certificates_06.jpg"><img class="alignnone size-full wp-image-327" title="place-all-certificates_06" src="http://www.blogotec.fr/wp-content/uploads/2009/03/place-all-certificates_06.jpg" alt="place-all-certificates_06" width="377" height="284" /></a></p>
<ul>
<li>Supprimer le certificat certnew.p7b stocké localement une fois qu&#8217;il est importé</li>
</ul>
<p> </p>
<p> </p>
<h2>2. Créer et installer un certificat serveur</h2>
<p>Depuis les serveurs en System Center Operation Manager ayant comme fonction, Serveur en DMZ, RMS et MS</p>
<p>Se connecter au serveur de certificat : <a href="http://certserv.domain.com/cersrv">http://certserv.domain.com/cersrv</a></p>
<ul>
<li>Demander un certificat</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/demander-un-certificat_07.jpg"><img class="alignnone size-full wp-image-328" title="demander-un-certificat_07" src="http://www.blogotec.fr/wp-content/uploads/2009/03/demander-un-certificat_07.jpg" alt="demander-un-certificat_07" width="468" height="163" /></a></p>
<ul>
<li>Demande Avancée</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/demande-avancee_08.jpg"><img class="alignnone size-full wp-image-329" title="demande-avancee_08" src="http://www.blogotec.fr/wp-content/uploads/2009/03/demande-avancee_08.jpg" alt="demande-avancee_08" width="259" height="190" /></a></p>
<ul>
<li>Soumettre une demande de certificat auprès de cette autorité de certification en utilisant un formulaire</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/soumettre-une-demande_09.jpg"><img class="alignnone size-full wp-image-330" title="soumettre-une-demande_09" src="http://www.blogotec.fr/wp-content/uploads/2009/03/soumettre-une-demande_09.jpg" alt="soumettre-une-demande_09" width="609" height="138" /></a></p>
<ul>
<li>Remplir les champs ci-dessous</li>
<li>o Nom</li>
<li>o Type: Other</li>
<li>o OID: 1.3.6.1.5.5.7.3.1, 1.3.6.1.5.5.7.3.2</li>
<li>o Mark keys as exportable</li>
<li>o Use local machine store</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/other-oid_10.jpg"><img class="alignnone size-full wp-image-331" title="other-oid_10" src="http://www.blogotec.fr/wp-content/uploads/2009/03/other-oid_10.jpg" alt="other-oid_10" width="489" height="493" /></a></p>
<p> </p>
<ul>
<li>Approuver la demande en attente de certificat sur le serveur de certificat</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/pending-request_11.jpg"><img class="alignnone size-full wp-image-332" title="pending-request_11" src="http://www.blogotec.fr/wp-content/uploads/2009/03/pending-request_11.jpg" alt="pending-request_11" width="609" height="172" /></a></p>
<ul>
<li>Se connecter au site <a href="http://certserv.domain.com/cersrv">http://certserv.domain.com/cersrv</a> et cliquez sur vérifier un certificat en attente</li>
</ul>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/verifier-certificat-attente_12.jpg"><img class="alignnone size-full wp-image-333" title="verifier-certificat-attente_12" src="http://www.blogotec.fr/wp-content/uploads/2009/03/verifier-certificat-attente_12.jpg" alt="verifier-certificat-attente_12" width="488" height="154" /></a></p>
<p> <a href="http://www.blogotec.fr/wp-content/uploads/2009/03/pending_13.jpg"><img class="alignnone size-full wp-image-335" title="pending_13" src="http://www.blogotec.fr/wp-content/uploads/2009/03/pending_13.jpg" alt="pending_13" width="437" height="138" /></a></p>
<ul>
<li>Installer le certificat</li>
</ul>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/install_14.jpg"><img class="alignnone size-full wp-image-337" title="install_14" src="http://www.blogotec.fr/wp-content/uploads/2009/03/install_14.jpg" alt="install_14" width="272" height="138" /></a></p>
<p> </p>
<h2>3. Export des certificats</h2>
<p>Depuis les serveurs en DMZ, RMS et MS</p>
<ul>
<li>Ouvrir une MMC de certificat Computer Account / Local Computer</li>
<li>Dans le dossier Personal\Certificates export du certificat</li>
</ul>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/export_certificat_15.jpg"><img class="alignnone size-full wp-image-338" title="export_certificat_15" src="http://www.blogotec.fr/wp-content/uploads/2009/03/export_certificat_15.jpg" alt="export_certificat_15" width="514" height="226" /></a></p>
<ul>
<li>Export the private keys</li>
</ul>
<p><span style="color: #0000ee; text-decoration: underline;"><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/export-private-keys_16.jpg"><img class="alignnone size-full wp-image-339" title="export-private-keys_16" src="http://www.blogotec.fr/wp-content/uploads/2009/03/export-private-keys_16.jpg" alt="export-private-keys_16" width="324" height="252" /></a></span></p>
<ul>
<li>Sélectionner Personal Information et Enable Strong Protection</li>
</ul>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/personnal_17.jpg"><img class="alignnone size-full wp-image-340" title="personnal_17" src="http://www.blogotec.fr/wp-content/uploads/2009/03/personnal_17.jpg" alt="personnal_17" width="375" height="290" /></a></p>
<ul>
<li>Taper un password</li>
</ul>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/password_18.jpg"><img class="alignnone size-full wp-image-341" title="password_18" src="http://www.blogotec.fr/wp-content/uploads/2009/03/password_18.jpg" alt="password_18" width="375" height="290" /></a></p>
<ul>
<li>Exporter le certificat *.pfx</li>
</ul>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/export_19.jpg"><img class="alignnone size-full wp-image-342" title="export_19" src="http://www.blogotec.fr/wp-content/uploads/2009/03/export_19.jpg" alt="export_19" width="373" height="138" /></a></p>
<h2><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/export_19.jpg"></a>4. Installation Manuel de l&#8217;agent</h2>
<ul>
<li>Configurer le MG et le fichier host si besoin</li>
</ul>
<h2>5. Importation du certificat dans SCOM</h2>
<p>Utilisation de l&#8217;exécutable Momcertimport.exe disponible sur le CD Rom d&#8217;installation dans le dossier Support Tools</p>
<p>Pour les agents installés en 64bits utiliser l&#8217;executable Momcertimport.exe disponible dans le dosser amd64.</p>
<p>Commande : momcertimport.exe c:\certificat.pfx</p>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/momcert_20.jpg"><img class="alignnone size-full wp-image-343" title="momcert_20" src="http://www.blogotec.fr/wp-content/uploads/2009/03/momcert_20.jpg" alt="momcert_20" width="352" height="59" /></a></p>
<p>Vérifier la présence du binnaire ChannelCertificateSerialNumber dans HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Operations Manager\3.0\Machine Settings</p>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/regedit_21.jpg"><img class="alignnone size-full wp-image-344" title="regedit_21" src="http://www.blogotec.fr/wp-content/uploads/2009/03/regedit_21.jpg" alt="regedit_21" width="609" height="137" /></a></p>
<p> </p>
<h2>6. Approuver l&#8217;installation Manuelle</h2>
<p><a href="http://www.blogotec.fr/wp-content/uploads/2009/03/manual_22.jpg"><img class="alignnone size-full wp-image-345" title="manual_22" src="http://www.blogotec.fr/wp-content/uploads/2009/03/manual_22.jpg" alt="manual_22" width="520" height="160" /></a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-knowledge">
<ul class="socials">
		<li class="shr-facebook">
			<a href="http://www.shareaholic.com/api/share/?title=SCOM+2007+%3A+Comment+d%C3%A9ployer+un+agent+en+DMZ+avec+certificat&amp;link=http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/&amp;notes=D%C3%A9ploiement%20d%27un%20agent%20en%20DMZ%0D%0A%C2%A0%0D%0A%0D%0Ahow%20to%20deploy%20agent%20on%20DMZ%2Fcomment%20deployer%20un%20agent%20en%20dmz%0D%0A1.%20Import%20du%20certificat%20d%27autorit%C3%A9%0D%0AAction%20%C3%A0%20r%C3%A9aliser%20depuis%20les%20serveurs%20en%20DMZ%2C%20RMS%20et%20MS%0D%0A%0D%0ASe%20connecter%20au%20serveur%20de%20certificat%C2%A0%3A%20http%3A%2F%2Fcertserv.domain.com%2Fcersrv%0D%0A%0D%0A%09R%C3%A9cup%C3%A9rer%20le%20certifica&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=5&amp;tags=&amp;ctype=" rel="nofollow" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-mail">
			<a href="http://www.shareaholic.com/api/share/?title=SCOM%202007%20%3A%20Comment%20d%C3%A9ployer%20un%20agent%20en%20DMZ%20avec%20certificat&amp;link=http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/&amp;notes=D%C3%A9ploiement%20d%27un%20agent%20en%20DMZ%0D%0A%C2%A0%0D%0A%0D%0Ahow%20to%20deploy%20agent%20on%20DMZ%2Fcomment%20deployer%20un%20agent%20en%20dmz%0D%0A1.%20Import%20du%20certificat%20d%27autorit%C3%A9%0D%0AAction%20%C3%A0%20r%C3%A9aliser%20depuis%20les%20serveurs%20en%20DMZ%2C%20RMS%20et%20MS%0D%0A%0D%0ASe%20connecter%20au%20serveur%20de%20certificat%C2%A0%3A%20http%3A%2F%2Fcertserv.domain.com%2Fcersrv%0D%0A%0D%0A%09R%C3%A9cup%C3%A9rer%20le%20certifica&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=201&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-printfriendly">
			<a href="http://www.shareaholic.com/api/share/?title=SCOM+2007+%3A+Comment+d%C3%A9ployer+un+agent+en+DMZ+avec+certificat&amp;link=http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/&amp;notes=D%C3%A9ploiement%20d%27un%20agent%20en%20DMZ%0D%0A%C2%A0%0D%0A%0D%0Ahow%20to%20deploy%20agent%20on%20DMZ%2Fcomment%20deployer%20un%20agent%20en%20dmz%0D%0A1.%20Import%20du%20certificat%20d%27autorit%C3%A9%0D%0AAction%20%C3%A0%20r%C3%A9aliser%20depuis%20les%20serveurs%20en%20DMZ%2C%20RMS%20et%20MS%0D%0A%0D%0ASe%20connecter%20au%20serveur%20de%20certificat%C2%A0%3A%20http%3A%2F%2Fcertserv.domain.com%2Fcersrv%0D%0A%0D%0A%09R%C3%A9cup%C3%A9rer%20le%20certifica&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=236&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Send this page to Print Friendly">Send this page to Print Friendly</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.shareaholic.com/api/share/?title=SCOM+2007+%3A+Comment+d%C3%A9ployer+un+agent+en+DMZ+avec+certificat&amp;link=http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/&amp;notes=D%C3%A9ploiement%20d%27un%20agent%20en%20DMZ%0D%0A%C2%A0%0D%0A%0D%0Ahow%20to%20deploy%20agent%20on%20DMZ%2Fcomment%20deployer%20un%20agent%20en%20dmz%0D%0A1.%20Import%20du%20certificat%20d%27autorit%C3%A9%0D%0AAction%20%C3%A0%20r%C3%A9aliser%20depuis%20les%20serveurs%20en%20DMZ%2C%20RMS%20et%20MS%0D%0A%0D%0ASe%20connecter%20au%20serveur%20de%20certificat%C2%A0%3A%20http%3A%2F%2Fcertserv.domain.com%2Fcersrv%0D%0A%0D%0A%09R%C3%A9cup%C3%A9rer%20le%20certifica&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=88&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-viadeo">
			<a href="http://www.shareaholic.com/api/share/?title=SCOM+2007+%3A+Comment+d%C3%A9ployer+un+agent+en+DMZ+avec+certificat&amp;link=http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/&amp;notes=D%C3%A9ploiement%20d%27un%20agent%20en%20DMZ%0D%0A%C2%A0%0D%0A%0D%0Ahow%20to%20deploy%20agent%20on%20DMZ%2Fcomment%20deployer%20un%20agent%20en%20dmz%0D%0A1.%20Import%20du%20certificat%20d%27autorit%C3%A9%0D%0AAction%20%C3%A0%20r%C3%A9aliser%20depuis%20les%20serveurs%20en%20DMZ%2C%20RMS%20et%20MS%0D%0A%0D%0ASe%20connecter%20au%20serveur%20de%20certificat%C2%A0%3A%20http%3A%2F%2Fcertserv.domain.com%2Fcersrv%0D%0A%0D%0A%09R%C3%A9cup%C3%A9rer%20le%20certifica&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=92&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Viadeo">Share this on Viadeo</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=SCOM+2007+%3A+Comment+d%C3%A9ployer+un+agent+en+DMZ+avec+certificat&amp;link=http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/&amp;notes=D%C3%A9ploiement%20d%27un%20agent%20en%20DMZ%0D%0A%C2%A0%0D%0A%0D%0Ahow%20to%20deploy%20agent%20on%20DMZ%2Fcomment%20deployer%20un%20agent%20en%20dmz%0D%0A1.%20Import%20du%20certificat%20d%27autorit%C3%A9%0D%0AAction%20%C3%A0%20r%C3%A9aliser%20depuis%20les%20serveurs%20en%20DMZ%2C%20RMS%20et%20MS%0D%0A%0D%0ASe%20connecter%20au%20serveur%20de%20certificat%C2%A0%3A%20http%3A%2F%2Fcertserv.domain.com%2Fcersrv%0D%0A%0D%0A%09R%C3%A9cup%C3%A9rer%20le%20certifica&amp;short_link=&amp;shortener=google&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%2524%257Btitle%257D%2B-%2B%2524%257Bshort_link%257D%2Bvia%2B%2540Shareaholic&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

]]></content:encoded>
			<wfw:commentRss>http://www.blogotec.fr/scom/scom-2007-comment-deployer-un-agent-en-dmz-avec-certificat/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

