RE: PKI V2 Certificates OS level
- From: briandel@xxxxxxxxxxxxxxxxxxxx (Brian Delaney [MSFT])
- Date: Thu, 15 Feb 2007 01:42:23 GMT
Hi Scott,
In order to issue v2 certificate templates (which are actually v3
certificates) you must publish the templates on a 2003 Enterprise Edition
CA. Generally speaking you would use a Stand-Alone Root CA running Windows
Server 2003 Standard edition as an offline root and have enterprise
subordinate CAs running Windows Server 2003 Enterprise Edition for
certificate issuance.
The root ca is in no way used to issue a certificate on the subordinate ca.
The only time the root ca is used is for issuing certificates to new
subordinate ca's, renewing subordinate ca certificates and publishing CRL's.
Hope this helps,
Brian Delaney
Microsoft Canada
--
This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: PKI V2 Certificates OS levelWindows
thread-index: AcdQk9EyMMkdya3JQI2Q8lyYaXsbXg==
X-WBNR-Posting-Host: 66.212.115.49
From: =?Utf-8?B?U0I=?= <SB@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: PKI V2 Certificates OS level
Date: Wed, 14 Feb 2007 15:57:00 -0800
Hi folks,
I am currently working with a Certificates setup in my lab to become more
familiar with Certificates and PKI V2 Certificates. I have setup a
2k3 R2 Enterprise server with a Enterprise Root CA and have also setup afew
subordinate CAs on Windows 2k3 R2 Standard server. From everything I haveOS.
read, I know I have to have the Enterprise Root CA on an Enterprise 2k3
The question is will the subordinate CA's issue a PKI v2 certificaterequest
in this fasion? In otherwords if my logic is right, the Subordinate CAwould
process the request sending it back to the Enterprise CA for processingwhich
would then process and return it back through the Subordinate CA and backout
to the requesting party. Does this sound right? Will this senario work?I
would like to protect the Enterprise CA in this fasion letting thebest
subordinate CA's do the actual interaction for requests. I've read the
practices guide for setting up PKI v2 certificates but it still seemsvague
to me in what it is saying. Hense the testing I am going through above.
Thanks,
Scott
.
- Prev by Date: Re: Problem with the autentication server
- Next by Date: Re: Adprep W2000 to W2003 Server
- Previous by thread: Re: Problem with the autentication server
- Next by thread: Re: Adprep W2000 to W2003 Server
- Index(es):
Relevant Pages
|