Re: ADFS and Certificate Services

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



ADFS is not really related to becoming a certificate vendor. ADFS uses
certificates, but it won't help you with requesting or issuing certs.

Essentially, to become a certificates "reseller", you need a CA certificate
that is signed by another CA that is chained to a publicly trusted root. To
get such a CA certificate, you generally pay a fairly large amount of money
(a few hundred K$, depending on the types of certificates you will be
issuing and other stuff) and you will need to adhere strictly to the
policies of your issuing CA or else they may revoke your certificate and
causing every certificate you issued to become invalid. It is a fairly
serious responsibility. If you talk with your cert vendor (Verisign), I'm
sure they have some commercial offerings along these lines that they could
tell you about.

I don't really see how ADFS would work into this unless you provided a
web-based UI for your CA and wanted to secure it using ADFS (which you
certainly could).

If you explain more, I might be able to provide more details. I also
suggest following up in one of the crypto newsgroups if you want to talk to
others who are more experienced with setting up a commercial CA.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"nboothe" <nboothe@xxxxxxxxx> wrote in message
news:1176836055.067116.280730@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I posted a few weeks ago about the basics of ADFS and Joe was gracious
enough to help me. I've made some progress, but am beginning to think
my concept might not even be possible and I'm hoping someone can
advise.

My company wants to implement single sign on, but more importantly we
want to become our own certificate authority, using a Microsoft CA,
for our internal and external users to get S-MIME certs for encrypted
email. We currently pay verisign a yearly fee for every employee to
communicate with encrypted email. We want the CA to be available for
others to download the public keys so customers can communicate
securely. You might ask how does this relate to ADFS? Well, we want
to allow access to external employees to login to the CA to get an
updated cert if needed and provide access to other HR apps in the
process.

Is ADFS the solution for this concept? Is there a better way to
implement this concept? If there is a better group for this
question, let me know.

Thanks!



.



Relevant Pages

  • Re: Error issuing certificates from WS03 cert svc
    ... is able to issue end entity certs.Next, I restored the revoked CA certs. ... I still get the same error on the original issuing CA ... certificate. ... I'm having trouble with issuing certificates from a Windows Server 2003 ...
    (microsoft.public.windows.server.security)
  • Re: Error issuing certificates from WS03 cert svc
    ... I installed an additional issuing CA with the same configuration as the original. ... The new CA has no problem and is able to issue end entity certs.Next, I restored the revoked CA certs. ... in the Windows Application Log: "Certificate ... All certs are likewise published on the web server ...
    (microsoft.public.windows.server.security)
  • Re: ADFS and Sharepoint Issue
    ... and BAM ASP.NET 2.0 error message for a rejected certificate hash. ... So ADFS REJECTS the token, ... The problem is, I go through all of my redirects, I reach all of teh ADFS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Is it possible to authenticate a user against an untrusted dom
    ... certificate if it means modifying the original domain in any way (including ... To validate the U/P you can perform an LDAP bind. ... Services (ADFS). ... want to authenticate but I don't want a Windows trust" problem. ...
    (microsoft.public.platformsdk.security)
  • Re: ADFS and SSL Certificates
    ... to export the resource federation server authentication certificate to a file and import it on the Web server? ... But it isn't clear in the documentation how to set this thing up with a CA..... ... Yes You still need to export this certificate because it is needed to verify data signed by ADFS server. ...
    (microsoft.public.windows.server.active_directory)