ADFS and Certificate Services



I posted a few weeks ago about the basics of ADFS and Joe was gracious
enough to help me. I've made some progress, but am beginning to think
my concept might not even be possible and I'm hoping someone can
advise.

My company wants to implement single sign on, but more importantly we
want to become our own certificate authority, using a Microsoft CA,
for our internal and external users to get S-MIME certs for encrypted
email. We currently pay verisign a yearly fee for every employee to
communicate with encrypted email. We want the CA to be available for
others to download the public keys so customers can communicate
securely. You might ask how does this relate to ADFS? Well, we want
to allow access to external employees to login to the CA to get an
updated cert if needed and provide access to other HR apps in the
process.

Is ADFS the solution for this concept? Is there a better way to
implement this concept? If there is a better group for this
question, let me know.

Thanks!

.