Domain Controller Certificate Template Autoenrollment
There are also two windows server 2003 sp2 domain controllers which instead received a domain controller.
Domain controller certificate template autoenrollment. This combination allows the windows client to enroll users when they log on to their domain or a machine when it boots and keeps them periodically updated between these events. Both domain administrators from the root domain and enterprise administrators for fresh installations of windows server 2003 and newer domains may configure templates. These include machine computer domain controller and user certificates.
In a normal environment the auto enroll will start happening within minutes. Hard coded in this case means it is in the code it is not configured in any local or domain based policy. Certificate template is set up for autoenrollment when its settings are compatible with silent initial enrollment and renewal operations.
All domain controllers are hard coded to automatically enroll for a certificate based on the domain controller template if it is available for enrollment at a certificate authority in the forest. The following are default settings. It is something that is just turned on a good thing to clearify is that the acr for the domain controller template is not in the default domain controllers policy but hard coded into the os just as you say.
Certificate template permissions are also explained. Before you perform this procedure you must configure a server certificate template by using the certificate templates microsoft management console snap in on a ca that is running ad cs. I have this ad domain where a windows server 2003 sp2 enterprise root certification authority is operational and certificate autoenrollment is enabled both for users and computers.
Membership in both the enterprise admins and the root domain s domain admins group is the minimum required to complete this procedure. It replaces the domain controller authentication template. Most environments are not normal.
If you need more information about the new certificate templates shipped with a windows 2008 ca you can read this article. All fine and good every domain joined computer automatically gets a computer certificate issued. Certificate template acls are viewed in the certificate templates.