We're in the process of creating a new CA server and making new certs. A part of this change includes moving away from AD user based certificates to AD computer level certificate authentication. Can someone review my configuration profile before I implement this change to all of our Macs to ensure I'm following best practices?
We have the following:
1 configuration profile that includes the Root and Sub certificates
1 configuration profile that has the AD certificate settings and configurable wifi settings
Am I correct in thinking that both of these configuration profiles need to be combined into one?
In the past with user based certificates, we found that machines were randomly requesting new user certificates every so often, and sometimes would fail causing their machines to lose wifi. Has anyone had experience with the computer certificate above configuration and has had similar issues?