Re: Certificate services

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Marin Marinov (mlmarinov_at_askme.ca)
Date: 04/27/04


Date: Tue, 27 Apr 2004 10:25:55 -0400


<snip>
No, that's why it is a ROOT CA - nobody is above it, it issues and self-
signs its certificate. However, you can create an Enterprise subordinate
CA the parent of which is a standalone. When you design a CA hierarchy
the root should always be standalone since you'll be using it just for
certifying CAs at the lower tiers and most of the time it will be turned
off for security reasons. Check out the best practices for designing a
PKI whitepaper at Microsoft's site:
http://tinyurl.com/28cjx

If there's something specific you need to accomplish feel free to share
;)

-- 
Cheers,
   Marin Marinov
   MCT,MCSE 2003,MCSE:Security 2003
-
This posting is provided "AS IS" with no warranties, and confers no 
rights.


Relevant Pages

  • Re: Root certificate authority no longer added to client machines
    ... We have a standalone RootCA, ... Windows Server 2003 then you should be publishing the root ... certificate of the CA is added automatically to the Trusted Root ...
    (microsoft.public.security)
  • Re: Need advice for CA Model
    ... The root CA must be trusted on all the clients that will enroll to the ... certificates, each certificate must correspond to a user in AD with a UPN ... The enterprise CA automatically creates ... The second CA was a standalone ...
    (microsoft.public.win2000.security)
  • Re: Enterprise, Sub-ordinate or Standalone
    ... Is it standalone or enterprise?... ... Certificate Templates folder in the Certification Authority MMC snap- ... Windows SKU you're on. ... Is it a root or sub-ordinate?... ...
    (microsoft.public.windows.server.security)
  • Re: Need advice for CA Model
    ... > David, I see what you are saying and that makes sense. ... The certificate chain was issued by> an untrusted authority? ... >>> The original PKI model was a Root Enterprise CA, this is being used for>>> certificates for all internal users. ... The second CA was a standalone>>> subordinate, this was planned to be used for issuing users from outside>> the ...
    (microsoft.public.win2000.security)
  • Re: Signtool doesnt add entire chain when signing files
    ... you only need to ensure that the intermediate certificates are included in the signature so that the client can build a chain to the root. ... The root needs to be installed as a trusted root certificate on the client in order for the client to trust the certificate. ... Given that you don't have any intermediate certificates, it doesn't matter or not whether they are included in the signature so it should not matter if there is any difference between the wizard mode and the command line tool mode. ...
    (microsoft.public.platformsdk.security)