Click here to get back home

Re-Configuring LDAP CDP on Enterprise Root CA

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re-Configuring LDAP CDP on Enterprise Root CA Chipeater 02-17-2007
Posted by Chipeater on February 17, 2007, 1:31 am
Please log in for more thread options
Hi,
I'm deploying an enterprise root CA and want to re-confgure the LDAP
CDP container to not expose the CA's hostname, i.e. I replace the %%2
parameter with the %%7 parameter in the script used to reconfigure the
CA, so that the "CDP container name" is the same as the CA name.
However, I have observed problems with this:

A) I cannot control the default CDP the CA uses during installation,
therefore I automatically get a CDP container which reflects the CA
hostname.

B) If I do the reconfigure script immediately after deployment, the CA
cannot publish to the "%%7" container 'cus it doesn't exist.

I'm currently getting around these problems by doing the following:
1. Manually create the required CDP container before I do the CA
install, I use a certutil -dspublish to do this with a "fake CRL",
then throw away the CRL which is published

2. I install the CA and then run the reconfigure script and publish a
fresh CRL

3. I then have to delete the default "%%2" container and CRL which is
created by the CA install routine.

I'm not saying this is particularly hard, but in the context of a CA
ceremony it is not very elegant. Am I missing something, is there an
easier way to do this?

Hopefully, Chipeater


Posted by Brian Komar [MVP] on February 17, 2007, 1:54 pm
Please log in for more thread options
This would be the way to do it. What risk are you trying to mitigate
though? Is your CA deployed in a manner that it is exposed to the
Internet? Are you exposing your AD to the Internet for CRL retrieval?

Why not just use an HTTP URL if this is your concern?
Brian

david.wozny@gmail.com says...
> Hi,
> I'm deploying an enterprise root CA and want to re-confgure the LDAP
> CDP container to not expose the CA's hostname, i.e. I replace the %%2
> parameter with the %%7 parameter in the script used to reconfigure the
> CA, so that the "CDP container name" is the same as the CA name.
> However, I have observed problems with this:
>
> A) I cannot control the default CDP the CA uses during installation,
> therefore I automatically get a CDP container which reflects the CA
> hostname.
>
> B) If I do the reconfigure script immediately after deployment, the CA
> cannot publish to the "%%7" container 'cus it doesn't exist.
>
> I'm currently getting around these problems by doing the following:
> 1. Manually create the required CDP container before I do the CA
> install, I use a certutil -dspublish to do this with a "fake CRL",
> then throw away the CRL which is published
>
> 2. I install the CA and then run the reconfigure script and publish a
> fresh CRL
>
> 3. I then have to delete the default "%%2" container and CRL which is
> created by the CA install routine.
>
> I'm not saying this is particularly hard, but in the context of a CA
> ceremony it is not very elegant. Am I missing something, is there an
> easier way to do this?
>
> Hopefully, Chipeater
>
>

Posted by Chipeater on February 18, 2007, 2:01 am
Please log in for more thread options
Hi Brian,
I'm not suggesting that having the hostname in the LDAP CDP is a
risk... more a case of wanting things to be "neat and tidy". Perhaps
I should chill out. ;-)

I just wanted clarification that there's no slicker way of achieving
my requirement, which you've confirmed.

Many thanks, Dave


Similar ThreadsPosted
Migrate Enterprise root authority CA to stand-alone root CA December 13, 2005, 7:57 am
enabling LDAP over SSL: Enterprise CA in separate AD tree August 17, 2006, 6:31 pm
Stans-alone root CA or Enterprise root CA August 31, 2006, 6:32 pm
More than one enterprise root CA in a forest? January 18, 2006, 4:13 am
move enterprise root ca September 13, 2006, 8:09 am
Installing Enterprise Root CA March 3, 2007, 10:00 am
Moving Enterprise Root CA March 22, 2007, 11:05 am
EFS concerns before removing enterprise root CA March 23, 2007, 8:59 am
0x424 (WIN32: 1060) in Enterprise Root CA June 6, 2005, 9:03 am
Enterprise Root Certification Authority not trusted February 16, 2006, 2:07 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap