Hallo,
ich bin jetzt mit der Windows Server 2008 CA noch nicht so vertraut. Es sollte aber möglich sein, alle Rechner per GPO dazu zu bringen ein Zertifikat anzufordern:
Active Directory Certificate Services
Deploying certificates
User and computer certificates can be deployed by using a number of mechanisms, including autoenrollment, the Certificate Request Wizard, and Web enrollment. But deploying other types of certificates to a large number of computers can be challenging. In Windows Server 2003 it was possible to distribute trusted root CA certificates and enterprise trust certificates by using Group Policy. In Windows Server 2008 all of the following types of certificates can be distributed by placing them in the appropriate certificate store in Group Policy:
• Trusted root CA certificates
• Enterprise trust certificates
• Intermediate CA certificates
• Trusted publisher certificates
• Untrusted certificates
• Trusted people (peer trust certificates)
(Quelle:
Microsoft Corporation)