<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Matt Goedtel on Operations Management : Security</title><link>http://blogs.technet.com/mgoedtel/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Local Certificate Created on Agent Managed Device</title><link>http://blogs.technet.com/mgoedtel/archive/2007/08/22/local-certificate-created-on-agent-managed-device.aspx</link><pubDate>Wed, 22 Aug 2007 22:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1804389</guid><dc:creator>mgoedtel</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mgoedtel/comments/1804389.aspx</comments><wfw:commentRss>http://blogs.technet.com/mgoedtel/commentrss.aspx?PostID=1804389</wfw:commentRss><description>&lt;P&gt;So the other day I was presented with a question from my customer that I found interesting and did not have an immediate answer for.&amp;nbsp; The question was,&amp;nbsp;"why does Operations Manager 2007 create a certificate in the local store on an agent managed device?"&amp;nbsp; I was curious myself since all agent managed devices were in the same Forest/Domain as the Management Group, and therefore Kerberos authentication is used.&amp;nbsp; Hmm, let me research that further.&lt;/P&gt;
&lt;P&gt;Well I come to find out that the reason is the following as explained by the product group, "The certificates are generated for the Run As Execution feature.&amp;nbsp; When the agent is installed, the certificate is automatically generated and sent to the RMS, where it is used to provide an additional layer of encryption over RunAs related secrets.&amp;nbsp; This ensures the RunAs secrets can be securly transported from the RMS to the MS, and finally to the Agent."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;So there you have it.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1804389" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Operations+Manager+2007/default.aspx">Operations Manager 2007</category><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Security/default.aspx">Security</category></item></channel></rss>