Infrastructure prerequisites
Before configuring certificate enrollment for BigFix MCM, ensure that the required infrastructure components and access permissions are available. The certificate enrollment workflow relies on integration between Active Directory, Microsoft Certificate Services, NDES, and BigFix components.The following prerequisites should be verified before proceeding with the configuration steps described in this guide.
Active Directory Environment
- An operational Microsoft Active Directory domain must be available.
- Administrative access to the Active Directory environment is required to configure certificate templates and directory permissions.
Microsoft Certificate Authority (CA)
- A Microsoft Enterprise Certificate Authority must be deployed and integrated with Active Directory.
- Administrative access to the CA server is required to create and configure certificate templates used for SCEP enrollment.
-
The CA must be reachable from the NDES server.
Network Device Enrollment Service (NDES)
- A Windows Server must be available to install and configure Network Device Enrollment Service (NDES).
- Administrative privileges are required to install and configure the NDES role.
NDES Proxy Server
- A RHEL server must be available to deploy the NDES Proxy component used by BigFix.
- The NDES Proxy should be able to communicate with the NDES server and BigFix components.
LDAP Proxy Server
- A RHEL server must be available to deploy the LDAP Proxy component.
- The LDAP Proxy must be able to communicate with the Active Directory domain controllers.
BigFix Environment
Administrative access to the BigFix Console and Web UI is required to configure MCM, configure SCEP profiles and certificate enrollment settings.
Network and Access Requirements
Ensure the following communication paths are allowed between components:
- NDES Proxy → NDES Server
- NDES Server → Certificate Authority
- LDAP Proxy → Active Directory Domain Controllers
- BigFix MCM Server → NDES Proxy
- BigFix MCM Server → LDAP Proxy
All required ports must be open between these components as defined in the deployment architecture.