<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Deploying SCOM Gateway server</title>
	<atom:link href="http://bradstechblog.com/scom/deploying-scom-gateway-server/feed" rel="self" type="application/rss+xml" />
	<link>http://bradstechblog.com/scom/deploying-scom-gateway-server</link>
	<description>Microsoft technologies like: System Center Operations Manager, and whatever else comes up at the office.</description>
	<lastBuildDate>Mon, 22 Mar 2010 19:55:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-497</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Tue, 19 Jan 2010 17:58:09 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-497</guid>
		<description>Hi Krishna,

If I understand your question to be &quot;Can you use the IPSEc offline cert instead of a custom OpsMgr cert?&quot; 

I would say no. There are OID&#039;s that need to be part of the certificate. So in this case you will need to create it.  

I have not used 2008 R2 CA yet for Opsmgr. But yes, you can use this. I have seen many blogs as well that discuss this.

Hope this helps,
Brad</description>
		<content:encoded><![CDATA[<p>Hi Krishna,</p>
<p>If I understand your question to be &#8220;Can you use the IPSEc offline cert instead of a custom OpsMgr cert?&#8221; </p>
<p>I would say no. There are OID&#8217;s that need to be part of the certificate. So in this case you will need to create it.  </p>
<p>I have not used 2008 R2 CA yet for Opsmgr. But yes, you can use this. I have seen many blogs as well that discuss this.</p>
<p>Hope this helps,<br />
Brad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Krishna</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-495</link>
		<dc:creator>Krishna</dc:creator>
		<pubDate>Mon, 18 Jan 2010 10:25:21 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-495</guid>
		<description>Hello Brad,

Thank you for this Artilce

We are planning to Monitor our servers in DMZ throught Scom, will IPSec (Offline Request) custom certicate can be used for this as well ?

Currently I have CA installed on  Windows 2003 Standard edition which is also a DC and we are planning to migrate to Windows 2008 enterprise or Windows 2008 R2 Standard as this supports V1, V2, V3 certificate templates.

Currently we are running on SCOM 2007 SP1 and all servers are windows 2003.

Kindly Advice if i need to make sure for any other prerequistes.  Will windows 2008 R2 CA will suites our requirement

Regards,
Krishna
http://smtpport25.wordpress.com</description>
		<content:encoded><![CDATA[<p>Hello Brad,</p>
<p>Thank you for this Artilce</p>
<p>We are planning to Monitor our servers in DMZ throught Scom, will IPSec (Offline Request) custom certicate can be used for this as well ?</p>
<p>Currently I have CA installed on  Windows 2003 Standard edition which is also a DC and we are planning to migrate to Windows 2008 enterprise or Windows 2008 R2 Standard as this supports V1, V2, V3 certificate templates.</p>
<p>Currently we are running on SCOM 2007 SP1 and all servers are windows 2003.</p>
<p>Kindly Advice if i need to make sure for any other prerequistes.  Will windows 2008 R2 CA will suites our requirement</p>
<p>Regards,<br />
Krishna<br />
<a href="http://smtpport25.wordpress.com" rel="nofollow">http://smtpport25.wordpress.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-492</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Fri, 18 Dec 2009 13:48:42 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-492</guid>
		<description>Jacob,

You will need both the custom certificate and root certificate for all your management servers. This includes your RMS, all MS servers and any gateways that you have. And remember that after you have imported these certs on each server using the MMC certificate tool, you will then need to use the SCOM certimport utility on each server to update the registry with the certificate serial number.

Brad</description>
		<content:encoded><![CDATA[<p>Jacob,</p>
<p>You will need both the custom certificate and root certificate for all your management servers. This includes your RMS, all MS servers and any gateways that you have. And remember that after you have imported these certs on each server using the MMC certificate tool, you will then need to use the SCOM certimport utility on each server to update the registry with the certificate serial number.</p>
<p>Brad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-491</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Wed, 16 Dec 2009 23:51:42 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-491</guid>
		<description>Thanks for the reply and do we need custom certificate for RMS and MS?</description>
		<content:encoded><![CDATA[<p>Thanks for the reply and do we need custom certificate for RMS and MS?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-489</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Tue, 15 Dec 2009 13:45:47 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-489</guid>
		<description>Hi Jacob,

You will need a personalized cert for each server that you will monitor without a gateway. Or a cert for each Gateway. This is partly because each cert needs to be named accordingly to the server name. Also, you will need to run the certimport utility on each server. This tool is used to copy the certificate serial number from the cert into the following registry location HKLM\Software\Microsoft\Microsoft Operations Manager\3.0\Machine Settings\ChannelCertificateSerialNumber 

A bit of a pain i know. But also a motivator to use a gateway server to minimize the work where possible.</description>
		<content:encoded><![CDATA[<p>Hi Jacob,</p>
<p>You will need a personalized cert for each server that you will monitor without a gateway. Or a cert for each Gateway. This is partly because each cert needs to be named accordingly to the server name. Also, you will need to run the certimport utility on each server. This tool is used to copy the certificate serial number from the cert into the following registry location HKLM\Software\Microsoft\Microsoft Operations Manager\3.0\Machine Settings\ChannelCertificateSerialNumber </p>
<p>A bit of a pain i know. But also a motivator to use a gateway server to minimize the work where possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-488</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Mon, 14 Dec 2009 23:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-488</guid>
		<description>Am confused on one thing, do we need to create custom certificate for each servers and have to register same on respective servers using momcertimport?</description>
		<content:encoded><![CDATA[<p>Am confused on one thing, do we need to create custom certificate for each servers and have to register same on respective servers using momcertimport?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steeve Theriault</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-487</link>
		<dc:creator>Steeve Theriault</dc:creator>
		<pubDate>Tue, 08 Dec 2009 00:10:58 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-487</guid>
		<description>Thai, to be able to see the certificate templates thecertificate authority has to be a windows enteprise version as it support v2 certificate.</description>
		<content:encoded><![CDATA[<p>Thai, to be able to see the certificate templates thecertificate authority has to be a windows enteprise version as it support v2 certificate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Hearn</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-481</link>
		<dc:creator>Brad Hearn</dc:creator>
		<pubDate>Wed, 14 Oct 2009 12:20:56 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-481</guid>
		<description>SorryThai I have not had the time to run through the process on a 2008 Cert server. This process is based on 2003. When i get the time I do plan to create a process for 2008.</description>
		<content:encoded><![CDATA[<p>SorryThai I have not had the time to run through the process on a 2008 Cert server. This process is based on 2003. When i get the time I do plan to create a process for 2008.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thais</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-479</link>
		<dc:creator>Thais</dc:creator>
		<pubDate>Tue, 06 Oct 2009 09:26:15 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-479</guid>
		<description>Trying out this &quot;walkthrough&quot; and got to point 3. &quot;Add new custom cert to.....&quot;. I cannot see the Certificate templates anywhere under Certification Authority. Maybe I&#039;m blind so I think I need some help with this.
The gateway server is installed on a 2008 Standard Server</description>
		<content:encoded><![CDATA[<p>Trying out this &#8220;walkthrough&#8221; and got to point 3. &#8220;Add new custom cert to&#8230;..&#8221;. I cannot see the Certificate templates anywhere under Certification Authority. Maybe I&#8217;m blind so I think I need some help with this.<br />
The gateway server is installed on a 2008 Standard Server</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fredrik</title>
		<link>http://bradstechblog.com/scom/deploying-scom-gateway-server/comment-page-1#comment-468</link>
		<dc:creator>Fredrik</dc:creator>
		<pubDate>Fri, 26 Jun 2009 08:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://bradstechblog.com/?p=246#comment-468</guid>
		<description>Just want to say thank you!
Looked all over (2 days)on how to create the template on windows 2008 CA. All other manuals i&#039;ve seen assume you already created the template and don&#039;t mention how to.
Thanks again</description>
		<content:encoded><![CDATA[<p>Just want to say thank you!<br />
Looked all over (2 days)on how to create the template on windows 2008 CA. All other manuals i&#8217;ve seen assume you already created the template and don&#8217;t mention how to.<br />
Thanks again</p>
]]></content:encoded>
	</item>
</channel>
</rss>
