Re: Installing Certification Authority server for SSL OWA

Tech-Archive recommends: Fix windows errors by optimizing your registry



There's great guidance on setting up your PKI on technet. You want to have at least 2 CAs. An offline Stand-alone Root CA on a non-domain member and an Enterprise Subordinate CA that is a domain member (but not on a DC).

A good start: http://technet2.microsoft.com/windowsserver/en/library/59f1dc5d-8720-419f-b7bf-3acf1dc549241033.mspx?mfr=true
One document is here: http://www.microsoft.com/downloads/details.aspx?FamilyId=CDB639B3-010B-47E7-B234-A27CDA291DAD&displaylang=en

Also look for anything by Brian Komar, who has a brand new Windows 2008 PKI book out by the way.


"achen" <achen2002@xxxxxxxxx> wrote in message news:d81256b4-24be-4cf4-a793-052f85f6a39c@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
We have decided to install a CA server for users to securely access
OWA and Outlook Anywhere 2007 from outside the corp network, however I
am a little bit confused in 4 different roles:

-Enterprise Root CA
-Enterprise Subordinate CA
-Stand-alone Root CA
-Stand-alone Subordinate CA

The CA server will be a domain member, the clients will be from
anywhere on the Internet (not VPN connected), which type of CA should
I install? And the reason?


.



Relevant Pages

  • Re: Standalone Root- Standalone Sub
    ... That is a decision you have to make based on the security needs of your ... organization, what PKI is used for, and how important PKI is to it your ... Usually the subordinate is recommended so that the ... root CA can be kept offline to protect the integrity of your PKI. ...
    (microsoft.public.security)
  • Re: A PE resource directory -- difficulty in understanding it ...
    ... nowhere there is mentioned that those four levels (root, ... name/ID, language-split, data) are the required and/or the only ones. ... it allowed for the root to directly point to the data (a leaf node)? ... in the info I found the "OffsetToData" member of the ...
    (microsoft.public.win32.programmer.kernel)
  • Re: Edgar Allen Poe, ROOT BOY and AS3
    ... graduating in 1967. ... He was a member of the Delta Kappa Epsilon fraternity. ... Root was a year older than Bush. ... While at Yale, he formed a band named Prince La La and the Midnight ...
    (alt.support.stop-smoking)
  • Re: CUPS admin
    ... chrisc and rose. ... What group is chrisc a member of and not rose? ... this system - all root commands are done with sudo.) ... If you have Gnome, use the system authorization menu in Gnome control ...
    (comp.os.linux.setup)
  • Re: The newgrp command
    ... Well, Ben you are right, root can switch to any group without having to give ... case an ordinary user is not a member of a particular group and she/he tries ... to use the newgrp command to switch to that group with correct password, ...
    (Fedora)