Axidian CertiFlow can work with Microsoft CAs that are located outside of the domain hosting the CertiFlow server. This could be a scenario where a company has several independent domains with separate CAs in each domain, with Axidian CertiFlow deployed only in one of those domains.
When issuing a smart card, Axidian CertiFlow addresses the MSCA Proxy, and the Proxy sends a request to the target CA using the Enrollment Agent certificate.
Follow these steps to install and configure the MSCA Proxy application:
Create a service account for Microsoft CA in an external domain.
Configure the Enrollment Agent certificate template for the service account and issue the certificate.
The Enrollment Agent certificate must reside in the certificate storage of a workstation (local computer) with CertiFlow.MSCA.Proxy component installed.
Install the CertiFlow.MSCA.Proxy.msi component on a workstation running in one domain with an external CA.