<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Network Access Protection (NAP) : NAP_book</title><link>http://blogs.technet.com/nap/archive/tags/NAP_5F00_book/default.aspx</link><description>Tags: NAP_book</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>The “Networking and NAP” book is included in the “Windows Server 2008 Resource Kit”</title><link>http://blogs.technet.com/nap/archive/2008/08/01/the-networking-and-nap-book-is-included-in-the-windows-server-2008-resource-kit.aspx</link><pubDate>Fri, 01 Aug 2008 22:52:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3096910</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/nap/comments/3096910.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3096910</wfw:commentRss><description>&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Greetings NAP fans! Guest NAP team blogger Joe Davies here with a somewhat self-serving blog entry.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;I just wanted to remind all of you that the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/MSPress/books/11160.aspx" mce_href="http://www.microsoft.com/MSPress/books/11160.aspx"&gt;&lt;FONT size=3&gt;Windows Server 2008 Networking and Network Access Protection (NAP)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; book from Microsoft Press, written by yours truly and Tony Northrup (a Microsoft MVP and highly prolific and experienced author), is now bundled in the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/mspress/books/10345.aspx" mce_href="http://www.microsoft.com/mspress/books/10345.aspx"&gt;&lt;FONT size=3&gt;Windows Server 2008 Resource Kit&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; from Microsoft Press. Obviously, if you purchase the &lt;I style="mso-bidi-font-style: normal"&gt;Windows Server 2008 Resource Kit&lt;/I&gt;, you do not also need to separately purchase the &lt;I style="mso-bidi-font-style: normal"&gt;Windows Server 2008 Networking and Network Access Protection&lt;/I&gt; book.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;You can get the &lt;I style="mso-bidi-font-style: normal"&gt;Windows Server 2008 Resource Kit&lt;/I&gt; from the following online book sellers:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet2 style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;A href="http://www.amazon.com/gp/product/0735623619/sr=1-1/qid=1156801743/ref=sr_1_1/104-6313703-3867159?ie=UTF8&amp;amp;s=books" mce_href="http://www.amazon.com/gp/product/0735623619/sr=1-1/qid=1156801743/ref=sr_1_1/104-6313703-3867159?ie=UTF8&amp;amp;s=books"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Amazon.com&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet2 style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;A href="http://search.barnesandnoble.com/booksearch/isbnInquiry.asp?isbn=0735623619" mce_href="http://search.barnesandnoble.com/booksearch/isbnInquiry.asp?isbn=0735623619"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Barnes and Noble&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=Bullet2 style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: Symbol; mso-ansi-language: EN; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;A href="http://www.quantumbooks.com/Merchant2/merchant.mvc?Screen=PROD&amp;amp;qts=mslearning&amp;amp;qtk=0735623619&amp;amp;Product_Code=0735623619" mce_href="http://www.quantumbooks.com/Merchant2/merchant.mvc?Screen=PROD&amp;amp;qts=mslearning&amp;amp;qtk=0735623619&amp;amp;Product_Code=0735623619"&gt;&lt;SPAN style="FONT-FAMILY: 'Trebuchet MS'"&gt;&lt;FONT size=3&gt;Quantum Books&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Although I wrote a lot of networking content for the &lt;/FONT&gt;&lt;A href="http://www.amazon.com/Microsoft-Windows-Server-Resource-Resource/dp/1572318058/ref=pd_bbs_sr_2?ie=UTF8&amp;amp;s=books&amp;amp;qid=1217618764&amp;amp;sr=1-2" mce_href="http://www.amazon.com/Microsoft-Windows-Server-Resource-Resource/dp/1572318058/ref=pd_bbs_sr_2?ie=UTF8&amp;amp;s=books&amp;amp;qid=1217618764&amp;amp;sr=1-2"&gt;&lt;FONT size=3&gt;Windows 2000 Server Resource Kit&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; and several books for Microsoft Press, this is the first time that one of my print books has made it into a Windows Server Resource Kit (…and there was much rejoicing.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;By the way, the Networking and NAP book is not the thickest book in the Resource Kit set. The &lt;I style="mso-bidi-font-style: normal"&gt;Windows Server 2008 Active Directory&lt;/I&gt; title is 827 pages, while the Networking and NAP book is only 817 pages. [Note to self: In the next version, add at least 11 pages with the text “This page intentionally left blank.” :&amp;gt; ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Enjoy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Joe Davies &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;P.S. The updates described in the &lt;/FONT&gt;&lt;A href="http://blogs.technet.com/nap/archive/2008/07/29/updates-to-health-certificate-information-in-the-windows-server-2008-networking-and-network-access-protection-nap-book.aspx" mce_href="http://blogs.technet.com/nap/archive/2008/07/29/updates-to-health-certificate-information-in-the-windows-server-2008-networking-and-network-access-protection-nap-book.aspx"&gt;&lt;FONT size=3&gt;July 29 NAP Team blog entry&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; apply to the version of the Networking and NAP book included in the current &lt;I style="mso-bidi-font-style: normal"&gt;Windows Server 2008 Resource Kit&lt;/I&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;P.P.S. The Amazon.com listing for the &lt;I style="mso-bidi-font-style: normal"&gt;Windows Server 2008 Resource Kit&lt;/I&gt; refers to NAP as “network aspect projection.” I am not sure what network aspect projection is, but it sounds pretty cool. Meanwhile, we are working with Amazon.com to get this corrected.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3096910" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/NAP_5F00_book/default.aspx">NAP_book</category></item><item><title>Updates to health certificate information in the "Windows Server 2008 Networking and Network Access Protection (NAP)" book</title><link>http://blogs.technet.com/nap/archive/2008/07/29/updates-to-health-certificate-information-in-the-windows-server-2008-networking-and-network-access-protection-nap-book.aspx</link><pubDate>Tue, 29 Jul 2008 23:25:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3095427</guid><dc:creator>MS NAP Team</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/nap/comments/3095427.aspx</comments><wfw:commentRss>http://blogs.technet.com/nap/commentrss.aspx?PostID=3095427</wfw:commentRss><description>&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Hello NAP fans! Joe Davies here, also known as &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/cc512738.aspx" mce_href="http://technet.microsoft.com/en-us/cc512738.aspx"&gt;&lt;FONT size=3&gt;The Cable Guy&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; for TechNet, reporting on some updates to the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/MSPress/books/11160.aspx" mce_href="http://www.microsoft.com/MSPress/books/11160.aspx"&gt;&lt;FONT size=3&gt;Windows Server 2008 Networking and Network Access Protection (NAP)&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; book from Microsoft Press.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Although we made every attempt to verify the information in the book, here are some updates based on last minute product changes and for stuff that we did not catch. Future printings of this book will reflect these changes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;1. On page 642, the text for the "Creating the Certificate Template for Health Certificates" section at the bottom of the page:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 1pt; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; mso-padding-alt: 1.0pt 0in 1.0pt 0in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For a Windows Server 2003–based NAP CA, you must manually create a System Health Authentication certificate template so that members of the IPsec exemption group can autoenroll a long-lived health certificate. For a Windows Server 2008–based NAP CA, a System Health Authentication certificate template is included.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Should be changed to the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 1pt; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; mso-padding-alt: 1.0pt 0in 1.0pt 0in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For a Windows Server 2008 or Windows Server 2003–based NAP CA, you must manually create a System Health Authentication certificate template so that members of the IPsec exemption group can autoenroll a long-lived health certificate.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;2. On page 643, the following block of text:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 1pt; BORDER-BOTTOM: medium none; mso-element: para-border-div; mso-border-top-alt: solid windowtext .5pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-top-alt: solid windowtext .5pt; mso-padding-alt: 1.0pt 0in 0in 0in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;To Create a Health Certificate Template on a Windows Server 2003–based NAP CA&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;1. Click Start, click Run, type &lt;B style="mso-bidi-font-weight: normal"&gt;certtmpl.msc&lt;/B&gt;, and then press ENTER. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;2. In the details pane, right-click Workstation Authentication, and then click Duplicate Template. This template is used because it is already configured with the client authentication EKU. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;3. On the General tab, under Template Display Name, type &lt;B style="mso-bidi-font-weight: normal"&gt;System Health Authentication&lt;/B&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;4. Select the Publish Certificate In Active Directory check box. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;5. Click the Extensions tab, and then click double-click Application Policies. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;6. Click Add, and then click New. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;7. In the New Application Policy dialog box, under Name, type &lt;B style="mso-bidi-font-weight: normal"&gt;System Health Authentication&lt;/B&gt;, and under Object Identifier, type &lt;B style="mso-bidi-font-weight: normal"&gt;1.3.6.1.4.1.311.47.1.1&lt;/B&gt;. The Client Authentication application policy will already be present. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;8. Click OK three times, and then click the Security tab. Because the WorkStation Authentication template was duplicated, this template should have two application policies: Client Authentication and System Health Authentication. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;9. Click Add, type the name of your IPsec NAP exemption group (such as &lt;B style="mso-bidi-font-weight: normal"&gt;IPsec NAP Exemption&lt;/B&gt;), and then click OK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;10. On the Security tab, in the Groups Or User Names list, select the name of your IPsec NAP exemption group, and then select the Allow check box next to Autoenroll. Click OK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;For a Windows Server 2008–based NAP CA, you must ensure that the System Health Authentication certificate template has the appropriate permissions for autoenrollment in the IPsec NAP exemption group.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;To Configure the Permissions on the System Health Authentication Certificate Template&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;1. Click Start, click Run, type &lt;B style="mso-bidi-font-weight: normal"&gt;certtmpl.msc&lt;/B&gt;, and then press ENTER.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;2. In the details pane, right-click System Health Authentication.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;3. On the Security tab, click Add, type the name of your IPsec NAP exemption group, and then click OK.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .5pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .5pt; mso-padding-alt: 0in 0in 1.0pt 0in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;4. Click the name of your IPsec NAP exemption group, select the Allow check boxes next to Enroll and Autoenroll, and then click OK.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Should be changed to the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 1pt; BORDER-BOTTOM: medium none; mso-element: para-border-div; mso-border-top-alt: solid windowtext .5pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-top-alt: solid windowtext .5pt; mso-padding-alt: 1.0pt 0in 0in 0in"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;To Create a Health Certificate Template on a Windows Server 2008 or Windows Server 2003-Based NAP CA &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;1. Click Start, click Run, type &lt;B style="mso-bidi-font-weight: normal"&gt;certtmpl.msc&lt;/B&gt;, and then press ENTER. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;2. In the details pane, right-click Workstation Authentication, and then click Duplicate Template. This template is used because it is already configured with the client authentication EKU. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;3. For a Windows Server 2008-based NAP CA, click Windows Server 2008, Enterprise Edition in the Duplicate Template dialog box, and then click OK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;4. On the General tab, under Template Display Name, type &lt;B style="mso-bidi-font-weight: normal"&gt;System Health Authentication&lt;/B&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;5. Select the Publish Certificate In Active Directory check box. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;6. Click the Extensions tab, and then double-click Application Policies. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;7. For a Windows Server 2008-based NAP CA, click Add, double-click System Health Authentication, and then click OK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;8. For a Windows Server 2003-based NAP CA, click Add, and then click New. In the New Application Policy dialog box, under Name, type &lt;B style="mso-bidi-font-weight: normal"&gt;System Health Authentication&lt;/B&gt;, and under Object Identifier, type &lt;B style="mso-bidi-font-weight: normal"&gt;1.3.6.1.4.1.311.47.1.1&lt;/B&gt;. The Client Authentication application policy will already be present. Click OK three times.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;9. Click the Security tab. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;10. Click Add, type the name of your IPsec NAP exemption group (such as &lt;B style="mso-bidi-font-weight: normal"&gt;IPsec NAP Exemption&lt;/B&gt;), and then click OK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;11. On the Security tab, in the Groups Or User Names list, select the name of your IPsec NAP exemption group, and then select the Allow check box next to Enroll and Autoenroll. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 1pt; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .5pt"&gt;
&lt;P style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0in; BORDER-TOP: medium none; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; BORDER-LEFT: medium none; PADDING-TOP: 0in; BORDER-BOTTOM: medium none; mso-border-bottom-alt: solid windowtext .5pt; mso-padding-alt: 0in 0in 1.0pt 0in"&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;12. In the Groups Or User Names list, select the Domain Computers group, and then clear the Allow check box next to Enroll so that all of the check boxes are cleared. Click OK. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Please feel free to print these updates and tape or staple&amp;nbsp;them to pages 642 and 643 of your printed book so that your copy has the correct information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Thanks!&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN lang=EN style="FONT-FAMILY: 'Trebuchet MS'; mso-ansi-language: EN"&gt;&lt;FONT size=3&gt;Joe Davies&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN lang=EN style="mso-ansi-language: EN"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3095427" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/nap/archive/tags/NAP_5F00_book/default.aspx">NAP_book</category></item></channel></rss>