You can deploy the Certificate Enrollment Policy Web Service and the Certificate Enrollment Web Service to enable certificate ...

You can deploy the Certificate Enrollment Policy Web Service and the Certificate Enrollment Web Service to enable certificate enrollment across forests and from the Internet. Together, these Web services allow you to publish certificate policy to a domain in a different forest, enabling clients to autoenroll for certificates that allow access to resources in a forest in which they do not have an account. You can also enable clients to enroll for and renew certificates from the Internet by deploying these Web services in a perimeter network or extranet.