Re: Windows 2003 Certificate server

From: Miha Pihler (mihap-news_at_atlantis.si)
Date: 09/24/04


Date: Fri, 24 Sep 2004 19:52:58 +0200

Hi Chris,

If you require high security, you could setup offline CA server -- CA server
that is not connected to the network. This way you would still be able to
use Web Enrolment that will ease your work when enrolling.

Once you enroll and issue certificate (administrator has to issue (approve))
any certificate in Windows 2003 standalone CA setup (by default). Once
administrator issues (approves) certificate, you can access it again using
web interface and save .pfx file to hard drive.

I find it a bit strange that you have to install private key on VPN device
and public key on client. Usually it would be the other way around...

Here are some resources on how to setup Windows 2003 server CA.

Implementing and Administering Certificate Templates in Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03crtm.mspx

Best Practices for Implementing a Microsoft Windows Server2003 Public Key
Infrastructure
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx

PKI Enhancements in Windows XP Professional and Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/winxppro/plan/pkienh.mspx

Windows Server 2003 PKI Operations Guide
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03pkog.mspx

Managing a Windows Server 2003 Public Key Infrastructure
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/mngpki.mspx

Advanced Certificate Enrollment and Management
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/advcert.mspx

Mike

"Chris" <Chris@discussions.microsoft.com> wrote in message
news:93046E23-481E-4813-A0A8-A903EC646B1F@microsoft.com...
> I want to use Windows 2003 as a stand alone CA. The purpose of the server
> will be to manually issue certificates to be used for client to gateway
vpn
> connections.
> For security reasons, I want the entire request / approval process to be
> manual without web-enrollment. Once a request, has been sent and
approved
> the Public Key gets installed on the requesting computer. Where is the
> Private Key stored?
> I need access to both Keys, the Public Key for the user to install on
their
> home systems and the Private Key has to get loaded into the Third-Party
vpn
> gateway appliance.
>
> TIA
>



Relevant Pages

  • Re: Need help configuring Wireless Connection profile
    ... and I can only use the intel OR windows utility, not both at the same time. ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Cannot sync Windows mobile with sbs2003 server
    ... Windows Mobile OS to the SBS2003 server at work so that he can read e-mails. ... What certificate do Microsoft recommend here, and where can this be bought? ...
    (microsoft.public.pocketpc)
  • Re: Need help configuring Wireless Connection profile
    ... Now life is good in the Windows wireless world. ... now have a secure wireless setup within my small business server environment. ... "point" the info of the Radius authentication to your current Radius server. ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: X.509 and ssh
    ... certificate issued by a trusted party can access the server. ... When you extend their reach out to all these other forms of communication, and used by computer laymen, old-fashioned random public key strings is simply not at all feasibile. ...
    (comp.security.ssh)
  • Re: EAP-TLS with windows CE
    ... credentials at the login prompt for Windows Server 2003 on the server ... The certificate is a public thing, ... When the server asks the Windows CE device to identify itself, ... I could easily steal your authentication information. ...
    (microsoft.public.windowsce.platbuilder)