Cookies are used to collect information about you. Nexus uses this information to give you a better experience of the website (functional) and to count the pages you visit (statistics).
Click OK to give Nexus your consent to use cookies. Read more about Nexus' cookie policy.
To activate support for Enroll on behalf of (EOBO) you must create an enrollment agent softtoken (P12) containing the extended key usage Certificate Request Agent.
The created enrollment agent softtoken must be made available to the enrollment agent performing the enrollment request.
The enrollment agent certificate(s) must be configured for each handler in winep.properties in the Protocol Gateway instance that WinEP is connected to.
For each Protocol Gateway handler that should support EOBO, the configuration parameter handler.x.enrollmentAgent.certs.x is required. See "Example configuration EOBO".
Configuration
Restrict enrollment agent
You can restrict the enrollment agent to only be able to issue certificates for target users that are a part of or not a part of specific groups.
Use the configuration parameters enrollmentAgent.allowedGroups and enrollmentAgent.blockedGroups in the Protocol Gateway winep.properties file. See "Example configuration EOBO".
Example configuration EOBO
This is an example configuration for EOBO on the User template in winep.properties: