RE: PKI



Hi,

There's really not enough information here. How exactly are you using PKI
for remote access? Do all the users have their own certificate? Are you
using smart cards?

Generally speaking the quickest way to move to a new PKI is to plan and
build the new PKI and reissue all certs from the new CA. If you are
looking for an easier way then run the two roots at the same time using the
new PKI for all new/renewed certs while the old PKI only to republish CRLs,
revoke certs, etc.

Either way, spend some serious time planning the new PKI to ensure you get
it right. Check out www.microsoft.com/pki. Also, I'd recommend engaging
one of the groups at Microsoft to review and assist you with your PKI
design and implementation.

Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: PKI
thread-index: Acdta3EoKvwrkptoQZyDxagr1tELEg==
X-WBNR-Posting-Host: 207.46.19.168
From: =?Utf-8?B?cC5v?= <po@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: PKI
Date: Fri, 23 Mar 2007 09:51:03 -0700

Hi
I've instaled enterprise root ca, and remote access authenticated via
cert.
I want to implement PKI from the beginig. What should I do to preserve
remote
acces.
I plans to install root ca and one subordinate. Could work two root ca's
in
organization.
Could you give me some advice how to implement PKI.


.



Relevant Pages

  • Re: Required Root CAs and CTLs
    ... No, you cannot add those to a CTL, they must be left in their native form. ... > Would it be possible to just add these root CAs to a Certificate Trust ... > List made by the own PKI implementeted? ... Then require all PKIs issuing these certificates to be ...
    (microsoft.public.windows.server.security)
  • PKI - Issue Publishing to AD DS
    ... These surfaced when trying to publish my root ... and policy CA certs into my AD. ... Brian speaks of an incorrect %%6 value in the ... I'm COMPLETELY new to PKI, so any help is greatly appreciated:) ...
    (microsoft.public.security)
  • Re: why do X.509 certificates contain context-specific tags?
    ... checked, some of the root ... I personally encountered certificates with a subject DN where some of ... committee-based development which tries to tackle complexity by throwing ... This can be opposed to much simpler PKI ...
    (sci.crypt)
  • Re: Standalone Root- Standalone Sub
    ... That is a decision you have to make based on the security needs of your ... organization, what PKI is used for, and how important PKI is to it your ... Usually the subordinate is recommended so that the ... root CA can be kept offline to protect the integrity of your PKI. ...
    (microsoft.public.security)
  • Re: Ca mit externen Stammzertifikat
    ... Eure Zertifikat-ausstellende CA muss von einer allgemein vertrauten Root CA ... weitreichende Konsequenzen bezüglich Organisation und Betrieb der PKI nach ... Mailempfänger können sich dieses Zertifikat ... CA als Stammzertifikat importieren? ...
    (microsoft.public.de.security.netzwerk.sicherheit)