Click here to get back home

Certificate FQDN example.local domain using example.com certificate

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Certificate FQDN example.local domain using example.com certificate g18c 10-31-2006
Posted by g18c on October 31, 2006, 7:40 am
Please log in for more thread options
Hi, i have been able to setup certificates and radius authentication on

my example.local domain. I have my root enterprise CA issuing
certificates and all is well (certificates show rootca.example.local as

the issuer).

I am considering the posibilities of using certificates to sign the
users email, rather than roll out a new cert infrastructure can i
implement my own inhouse certificate infrastructure even though my
active directory domain name is example.local, whereas our email domain

is example.com?


Is there anyway which i can issue certificates to computers in the
active directory but use the example.com certificates instead?


I hope this makes sense


Thanks,


Chris


Posted by Gary Reynolds on October 31, 2006, 2:16 pm
Please log in for more thread options
Hi Chris,

The main thing that you need to consider is trust, the person receiving your
email must trust the root ca from which your certificate is issued in order
to verify that email has come from you. If you use you internal CA external
users will not trust your root CA. There are a number of public CA that can
provide you with a certificate for your issuing CA that is chained off a
trusted root CA certificate. This provides verification that you are who
you say you are.

Another option is use a user credential services that are specifically
designed to provide certificate for users to sign emails\docs and client
authentication. Similar to the free email certificate most public CA
provide but you control the enrollment and revocation of certificates. Have
a look at the Verisign and GeoTrust.

Gary.


> Hi, i have been able to setup certificates and radius authentication on
>
> my example.local domain. I have my root enterprise CA issuing
> certificates and all is well (certificates show rootca.example.local as
>
> the issuer).
>
> I am considering the posibilities of using certificates to sign the
> users email, rather than roll out a new cert infrastructure can i
> implement my own inhouse certificate infrastructure even though my
> active directory domain name is example.local, whereas our email domain
>
> is example.com?
>
>
> Is there anyway which i can issue certificates to computers in the
> active directory but use the example.com certificates instead?
>
>
> I hope this makes sense
>
>
> Thanks,
>
>
> Chris
>



Similar ThreadsPosted
Automatic certificate enrollment for local system failed after upgrading member server to domain controller August 25, 2005, 6:11 pm
About EFS and local certificate that I want to export May 4, 2007, 9:17 am
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am
Automatic certificate enrollment for local system failed August 3, 2006, 10:22 am
"No Certificate Templates Could Be Found" Error Message When User Requests Certificate from CA Web Enrollment Pages September 21, 2006, 1:31 pm
Create Certificate Request for Windows2003 certificate authority without using website March 22, 2006, 8:07 am
Problem when requesting a certificate to IIS server (certificate web enrollment) October 4, 2005, 9:50 am
Restrict AD-User to one X509 Certificate per Certificate template? July 12, 2007, 12:18 pm
Delivering certificate not in the same domain name ? April 2, 2008, 6:57 am
Online request of a certificate with CA in another domain January 26, 2007, 11:39 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap