> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/active-directory/group-policy.md).

# グループ ポリシー

この証明書登録は、 [XCEP](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-xcep) および [WSTEP](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-wstep/) これらのプロトコルは、最新のすべての Windows バージョンでネイティブにサポートされています。Active Directory 環境では、必要な設定をグループ ポリシー (GPO) で適用して、AD に参加しているコンピューターが SCEPman から証明書を登録できるようにできます。

このシナリオでは、証明書の完全自動展開のために 3 つのグループ ポリシー設定が必要です。

{% stepper %}
{% step %}

### CEP サーバーの登録

CEP (Certificate Enrollment Policy) サーバー (SCEPman の一部) は、Active Directory enrollment 用に SCEPman で構成されたすべての証明書テンプレートを含むポリシーを、認証済みクライアントに提供します。CEP サーバーは、クライアント側のレジストリに追加する必要があります。Windows には、GUI で必要な設定を構成するための GPO テンプレートが含まれています。

#### ポリシーの構成

証明書テンプレートの場合は `デバイス` および `DC`、次に移動する必要があります *コンピューターの構成* ハイブ。 `ユーザー`、次に移動します *ユーザーの構成* ハイブ。両方の種類の証明書テンプレートを使用する場合は、両方を構成する必要があります。その場合、通常は 2 つの GPO を使用し、1 つはユーザーの構成でユーザーに適用し、もう 1 つはコンピューターの構成でコンピューターに適用します。

<pre data-title="グループ ポリシー管理エディター (gpmc.msc) での設定場所"><code>コンピューターの構成 / ユーザーの構成
└-ポリシー
  └-Windows の設定
    └-セキュリティの設定
      └-公開キー ポリシー
<strong>        └-証明書サービス クライアント - 証明書登録ポリシー サーバー
</strong></code></pre>

設定で、一覧に新しい CEP サーバーを追加し、該当する入力欄にポリシー サーバー URI を入力します。この URI は SCEPman のホームページからコピーできます。スキームは次のとおりです `https://scepman.contoso.com/step/policy`。CEP サーバーを入力して検証したら、追加してダイアログを確認することで設定を完了できます。

{% hint style="warning" %}
構成プロセス中、クライアントはすでに CEP サーバーへの検証呼び出しを行います。そのため、構成に使用するアカウント コンテキストには、SCEPman の CEP エンドポイントにアクセスする権限、つまり Kerberos で認証できることと、SCEPman のポート 443 への送信ネットワーク アクセスが必要です。
{% endhint %}

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FX84wWn0ykjjnIqAoZC8a%2Fimage.png?alt=media&amp;token=c8a6049d-2864-4dea-9692-f72718244bfd" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
次をご覧ください [既知の問題](/ja/zheng-ming-shu-guan-li/active-directory/general-configuration.md#known-issues) CEP サーバーの検証中にエラーが発生した場合は、該当セクションを参照してください。
{% endhint %}

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FxR6zCRYX2tIgRQz0eb80%2Fimage.png?alt=media&amp;token=9f994ff2-7ea6-4361-b8c7-ae615627769e" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
既存の ADCS と並行して SCEPman CEP サーバーを使用する場合は、既定のサーバーを選択し、既存の登録ポリシーを保持するようにしてください。
{% endhint %}
{% endstep %}

{% step %}

### 自動登録を有効にする

CEP サーバーが登録されていれば、ユーザー/コンピューターは SCEPman から証明書を要求できます。通常は、ユーザー操作なしでこれを自動的に行わせたいはずです。そのためには、自動登録を有効にする必要があります。なお、Microsoft Active Directory Certificate Services (AD CS) で以前から自動登録を使用していた場合は、すでに有効になっている可能性があります。

<pre data-title="グループ ポリシー管理エディター (gpmc.msc) での設定場所"><code>コンピューターの構成 / ユーザーの構成
└-ポリシー
  └-Windows の設定
    └-セキュリティの設定
      └-公開キー ポリシー
<strong>        └-証明書サービス クライアント - 自動登録
</strong></code></pre>

必ず次をオンにしてください `証明書テンプレートを使用する証明書を更新する` ことで、自動登録が有効になります。

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2F46F7m4Xtc7YI1Z3h2Khl%2Fimage.png?alt=media&amp;token=4432b827-4bb5-42a1-9232-03bac576e0ab" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### 信頼されたルート CA をインストールする

登録ポリシー サーバーと自動登録の設定が整ったら、ターゲット デバイスまたはユーザーが SCEPman の CA 証明書を信頼していることを確認するだけです。そのためには、対応する GPO 設定に CA 証明書をインポートする必要があります。

<pre data-title="グループ ポリシー管理エディター (gpmc.msc) での設定場所"><code>コンピューターの構成 / ユーザーの構成
└-ポリシー
  └-Windows の設定
    └-セキュリティの設定
      └-公開キー ポリシー
        └-信頼されたルート証明機関
<strong>          └-インポート (コンテキスト メニュー)
</strong></code></pre>

<figure><img src="https://114237723-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fpm2U64nuLU0ZWpU9Cs7B%2Fimage.png?alt=media&amp;token=4f0169cc-4ef8-419d-88f8-37f4140cfc6f" alt=""><figcaption></figcaption></figure>

SCEPman のホームページから CA 証明書をダウンロードし、このダイアログで必ずインポートしてください。
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/active-directory/group-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
