Click here to get back home

Need some information about certificates

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Need some information about certificates Shawn 03-09-2006
Posted by Shawn on March 9, 2006, 5:54 pm
Please log in for more thread options
Hi.
Let me just start by saying that I have very very little experience with
certificates. That being said, let me explain what I need:
I'm creating a windows application that connects to our client's web
service. The web service is set up with WSE 2.0 and requires me to encrypt
and sign the data I send to it. I've been told that I need a server
certificate installed on the server running my application. The certificate
will be used to encrypt and sign the data that is being sent (using the
certificate's private key). Then we have to export our certificate with a
public key to our client so that they can use our certificate's public key
to decrypt the data. Does this sound right?

Anyway, my question is this: How do I create a request for this
certificate? I know that I can create a request for a certificate in IIS,
but it doesn't sound to me like this is the same kind of certificate that I
would be installing if I was hosting a web site with SSL/HTTPS. After all,
I'm not running any web applications on the server, just an application that
needs to encrypt and sign data sent to a web service through HTTP. Am I
wrong here? Is it the same kind of certificate I have to request? Or am I
right, and if so, is there another way of creating a request?

Any help is sooooo very much appreciated!!

Thanks,
Shawn

PS. We are using Windows Server 2003



Posted by Steven L Umbach on March 10, 2006, 9:24 pm
Please log in for more thread options
You may also want to post in the Microsoft.public.security.newsgroup. The
standard procedure is that you use a private key for signing and then the
receiver uses your public key to verify the signature but for encryption you
use an entities public key to encrypt the data and then the recipient uses
their private key to decrypt the data. Public keys are generally not secured
and freely distributed [while private keys must be secured] which would mean
in your scenario that it could be possible for someone other then the
intended recipient be able to derypt the data. That is the way that email
smine would work for secure email for instance. --- Steve


> Hi.
> Let me just start by saying that I have very very little experience with
> certificates. That being said, let me explain what I need:
> I'm creating a windows application that connects to our client's web
> service. The web service is set up with WSE 2.0 and requires me to
> encrypt
> and sign the data I send to it. I've been told that I need a server
> certificate installed on the server running my application. The
> certificate
> will be used to encrypt and sign the data that is being sent (using the
> certificate's private key). Then we have to export our certificate with a
> public key to our client so that they can use our certificate's public key
> to decrypt the data. Does this sound right?
>
> Anyway, my question is this: How do I create a request for this
> certificate? I know that I can create a request for a certificate in IIS,
> but it doesn't sound to me like this is the same kind of certificate that
> I
> would be installing if I was hosting a web site with SSL/HTTPS. After
> all,
> I'm not running any web applications on the server, just an application
> that
> needs to encrypt and sign data sent to a web service through HTTP. Am I
> wrong here? Is it the same kind of certificate I have to request? Or am I
> right, and if so, is there another way of creating a request?
>
> Any help is sooooo very much appreciated!!
>
> Thanks,
> Shawn
>
> PS. We are using Windows Server 2003
>
>



Similar ThreadsPosted
Encryption information request September 20, 2006, 3:52 pm
Can I restric the access to information on user in the AD August 10, 2006, 12:12 pm
Extracting information from secedit database files (sdb) December 15, 2005, 4:28 pm
Utility to list SACL information of AD object? February 1, 2007, 4:05 pm
FTC Loses Laptops - Compromises Information of Suspected Fraudsters June 24, 2006, 12:15 pm
System Volume Information folder visable on network! August 2, 2006, 4:11 am
User account management and information functions usage with trusteddomains October 27, 2005, 3:55 pm
User account management and information functions usage with trusteddomains November 2, 2005, 3:16 pm
info on the National Information Security Group (NAISG) + an invitation February 4, 2008, 9:34 pm
Certificates April 5, 2007, 5:38 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap