|
Posted by Mark Burnett on January 31, 2008, 3:34 pm
Please log in for more thread options
Correct, you would store each other's certs (and the certs that sign those
certs) in each other's store. Another option, if you don't already have PKI
in place, is to use free certs from cacert.org and have them as the CA.
Mark Burnett
> Hi there.
>
> I have been learning about PKI and AD CS. And there is alot of material
> about using active Directory to hand out certs.
> But what if you were in a non-domain environment. How would 2 companies
> use
> each other's certs? Let's say that company A and company B each had AD CS
> running on standalone machines. Let's say they each were part of a
> workgroup instead of a domain.
>
> In order to use each other's certts, would they need to manually exchange
> certs, put them each other's cert store, and also exchange the Root CA
> cert
> and put that in the certificate store (in two places I think)?
>
> Or am I thinking about this all wrong?
>
> Thanks for your help.
>
> Kristin
>
>
|