Jump to content

Recommended Posts

Posted

Morning all,

 

We deploy alwayson VPN, and always have to get people to sign in on site first to get their user cert. Is there anyway to create the user cert for them and add it in after the fact? We are now issuing devices to people who can't come into centre, and are having to add an old VPN to try and get the cert issued, then move them across, would be nice to be able to email/secure send them a cert to install!

 

Thanks

 

James

Posted
These are for existing users, and we have been asking them if we can reset, log in and then get them to reset again, which is the main option at the moment, just didn't know if we could get our CA to churn them out for us! Would cut out the extra step
Posted

I've encountered this, though it was mainly an issue in the start of lockdown when staff hadn't brought their laptops in before everything shut down. I also encounter an issue where the VPN and/or certificate just magically disappear from the user's profile/certificate store for absolutely no reason. It's there and working one day, they go to bed and get up the next morning to work remotely...and BAM...it's gone. I thought I'd found a solution to this...until it didn't work for a user and I was like "meh, staff are back on site now, so I won't investigate further".

 

We have the free version of Cisco Meraki deployed to all of our clients. We can use their cloud dashboard to remotely control the user's laptop when it's at home. I can then get that user to log onto RDS, open their certificate store on RDS and export the VPN certificate. I can then upload it to their OneDrive, exit RDS and download the certificate to their remote laptop. Once downloaded, I can install the certificate. This worked well a handful of times and the last time, it failed and despite the certificate being there, the VPN wouldn't connect. We deploy the VPN profile as a Script Application via SCCM, which simply executes the PowerShell script and configuration XML. I copied those files to OneDrive (I think I had to change some file extensions to bypass the file type block) and shared it with the necessary staff. I then downloaded it from their OneDrive and executed it. That installed/reinstalled the VPN profile.

 

We have Intune, though I never looked into the SCEP deployment that @Norphy mentioned. I'd like to check that out at some point.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...