Click here to get back home

Third party DC certificates

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Third party DC certificates gal.alton 10-09-2006
Posted by gal.alton on October 9, 2006, 7:43 am
Please log in for more thread options
Hi,
I am familiar with the procedure "Advanced Certificate Enrollment and
Management" from
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/advcert.mspx?pf=true#E6

my question is: I have an AD 2003 and no CA in my organization. The
only available CA is some open source CA held at another organization.

Is there a way to create a certificate and key pair at the other org.
and unstall the cert and keys at my DC later?

Tanks
Gal Alton


Posted by S. Pidgorny on October 16, 2006, 6:14 am
Please log in for more thread options
I think you can. You can even enroll offline and bring the certificate
across in a PKCS #12 (.pfx) package. Important stuff: subject is the DC
FQDN, and the cert is to contain both server and client authentication
attributes.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> Hi,
> I am familiar with the procedure "Advanced Certificate Enrollment and
> Management" from
>
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/advcert.mspx?pf=true#E6
>
> my question is: I have an AD 2003 and no CA in my organization. The
> only available CA is some open source CA held at another organization.
>
> Is there a way to create a certificate and key pair at the other org.
> and unstall the cert and keys at my DC later?
>
> Tanks
> Gal Alton
>



Similar ThreadsPosted
IPSEC policies using third party certificates June 9, 2005, 9:23 am
Certificate Templates and third party CSP January 5, 2006, 8:11 am
Smartcard logon with third-party CA without MS CA May 13, 2006, 2:01 am
How to close outgoing connections without using 3-rd party software? January 31, 2006, 1:34 pm
Is third-party middleware required when deploying smartcards? October 1, 2007, 12:02 pm
Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc January 30, 2006, 1:50 am
Using Self-Issued Certificate in lieu of 3rd Party Certificate July 20, 2007, 10:24 am
Certificates April 5, 2007, 5:38 pm
two CA certificates for IPSec or something... September 17, 2005, 3:58 pm
Certificates are not published October 17, 2005, 3:31 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap