Portablity of Certificate Services

From: Charles Gregory (CharlesGregory_at_discussions.microsoft.com)
Date: 01/25/05


Date: Tue, 25 Jan 2005 00:59:02 -0800

Hi,

I'm in the situation where I need to generate a certificate for an
application now so that I can distribute the public root and intermediate
certificates to clients in many different organisations. The application
won't be in-service for some months to come - but my window for getting the
public certs out there is in the next few weeks along with some other
software which is being distributed.

So - can I set up a dummy Stand-alone CA now - generate my root and
intermediate certifcates and then distribute those public keys? Then when
we've properly decided on the PKI design for our organisation, install a new
CA and import the root and intermediate certificates previously created
instead of creating new ones at that time? Then I'll be able to issue further
certificates based on my original root and intermediate certificates on my
new PKI infrastructure.

Does it matter if the new properly designed PKI uses off-line or Enterprise
CAs - does that make a difference to if I can import the previous keys?

Regards,
Charles



Relevant Pages

  • Re: Required Root CAs and CTLs
    ... No, you cannot add those to a CTL, they must be left in their native form. ... > Would it be possible to just add these root CAs to a Certificate Trust ... > List made by the own PKI implementeted? ... Then require all PKIs issuing these certificates to be ...
    (microsoft.public.windows.server.security)
  • Re: Required Root CAs and CTLs
    ... This feature is available in Windows 2003 through cross certification. ... Windows 2003 domain group policy you have two choices for PKI ... > Would it be possible to just add these root CAs to a Certificate Trust ... Then require all PKIs issuing these certificates to be ...
    (microsoft.public.windows.server.security)
  • Re: why do X.509 certificates contain context-specific tags?
    ... checked, some of the root ... I personally encountered certificates with a subject DN where some of ... committee-based development which tries to tackle complexity by throwing ... This can be opposed to much simpler PKI ...
    (sci.crypt)
  • Re: Enterprise root CA not re-trusted after manually deleted
    ... published) autoenrollment queries AD for CA certs and installs them. ... CA certs in AD). ... deleted root certs can automatically return or need a manual repair. ... If root CA certificates are distributed using autonenrollment (meaning ...
    (microsoft.public.windows.server.security)
  • Re: Certificate issue on Exchange ActiveSync setup (WM6) - UPDATE
    ... In the Certificates snap-in box it is very important you choose "Computer ... Finish out of the standalone boxes and view the Console Root window. ... should now see a Console Root folder, with a Certificates folder under it, ...
    (microsoft.public.pocketpc.activesync)