Click here to get back home

Published Certificates in Active Directory

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Published Certificates in Active Directory Stephen Krok 02-09-2006
Posted by Stephen Krok on February 9, 2006, 6:53 pm
Please log in for more thread options
I've been doing some tests with a certificate authority integrated into AD
and have some questions.

I am running windows 2003 server /w Windows XP desktops.
I have one domain, and all computers are members. The domain level is 2003.

I do not want to enable auto-enrollment at this time.

I've created UserA & UserB. Both users have visited the /certsrv page and
created User Certificates. Both users exported their public keys, which I
imported into their user accounts in Active Directory.

S/MIME
I am unable to send encrypted email until both accounts send each other a
digitally signed email. I understand this exchanges public keys, but why is
it necesarry when both computers are domain members and should be able to
grab the other users public key from AD?

TIA
--
Steve



Posted by neo [mvp outlook] on February 15, 2006, 7:05 pm
Please log in for more thread options
<guess> If the clients are using Outlook 2003 in cached mode, it should take
<= 24 hours for things to work themselves out. (Offline Address Book has to
be rebuilt and then the user's Outlook has to download the updated offline
address book.) </guess>

/neo


> I've been doing some tests with a certificate authority integrated into AD
> and have some questions.
>
> I am running windows 2003 server /w Windows XP desktops.
> I have one domain, and all computers are members. The domain level is
> 2003.
>
> I do not want to enable auto-enrollment at this time.
>
> I've created UserA & UserB. Both users have visited the /certsrv page and
> created User Certificates. Both users exported their public keys, which I
> imported into their user accounts in Active Directory.
>
> S/MIME
> I am unable to send encrypted email until both accounts send each other a
> digitally signed email. I understand this exchanges public keys, but why
> is it necesarry when both computers are domain members and should be able
> to grab the other users public key from AD?
>
> TIA
> --
> Steve
>
>



Similar ThreadsPosted
W2003 PKI: Publish certificates onto user objects in active directory December 14, 2005, 1:04 pm
Certificates are not published October 17, 2005, 3:31 pm
auditing active directory not working properly directory serviceaccess October 21, 2005, 7:47 pm
Linking PKI directory accounts with Active Directory? February 11, 2007, 5:29 am
Active Directory December 28, 2005, 7:00 am
eap-tls without active directory November 23, 2006, 10:52 am
Active Directory May 1, 2008, 11:11 am
Active Directory Server August 12, 2005, 3:49 pm
Active Directory Questions. November 24, 2006, 12:09 am
Active Directory Schema Permissions October 17, 2006, 4:59 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap