Click here to get back home

2003/R2 certificate server questions

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
2003/R2 certificate server questions eric.hall 03-13-2007
Posted by Brian Komar [MVP] on March 13, 2007, 9:24 pm
Please log in for more thread options
Inline

In article <1173817783.817437.149340
@n59g2000hsh.googlegroups.com>, eric.hall@gmail.com
says...
>
> wrote:
>
> > You really do not need an additional subordinate CA
> > running OPenSSL to service requests from Linux/samba
> > clients
>
> The business groups are managed separately. But it's nice to know--I
> did not think it was possible to run multiple cert authorities in the
> same machine with Windows Cert Services, since there is only a one-
> time setup.
>

You cannot install two instances (unless using
virtualization and running two separate boxes
virtually).
What I am saying is there is no need to create a
separate CA for the Linux/samba domain. You can delegate
certificate management at the CA if you require the
separation. For example, you can set up a certificate
manager restriction that Bob can only manage
certificates issued to domain1\domain users and Alice
can only manage certificate to domain2\domain users.

> > > That will also let me manually create/sign certificates for use in
> > > things like switches and whatnot? With W2k EE, it seemed to just do
> > > automatic certs for users and machines, so this is my main point of
> > > concern.
> >
> > Automatic certs, Key archival and recovery, customizable
> > certificate templates. Lots.
>
> Okay great. I guess all this stuff is in the templates, which is what
> choked me before. I'll go find the docs for this.

LOL. I wrote the whitepaper. It is posted at
www.microsoft.com/pki. Also, I have a book on PKI you
may find useful
(http://www.microsoft.com/MSPress/books/6745.aspx)

>
> > > I can also uninstall the sub CA, revoke the cert, and reissue new
> > > certs if I move the sub CA later, right? I mean, creating an
> > > "enterprise" sub-CA doesn't permanently alter the directory does it?
> >
> > You can definitely do this but high TCO
>
> Not a major concern in this case, since there are very few nodes and
> users in that organization.

Cool
>
> Thanks for the answers!
>
>

Similar ThreadsPosted
2003/R2 certificate server questions March 12, 2007, 10:24 pm
Assign manage printer rights via group policy? (2003r2) January 24, 2008, 4:44 am
Questions about the artical "DCOM Security Enhancements" for Windows Server 2003 SP1 January 15, 2006, 9:47 pm
Problem when requesting a certificate to IIS server (certificate web enrollment) October 4, 2005, 9:50 am
Wired 802.1x Questions May 1, 2006, 3:30 pm
Questions about CDP an AIA distribution points July 11, 2006, 7:41 am
antivirus software questions September 19, 2006, 2:25 pm
Active Directory Questions. November 24, 2006, 12:09 am
Questions about using IPsec across domains February 25, 2008, 5:47 pm
Security Questions and Answers for CLM April 29, 2008, 3:31 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap