Re: Cert Authority

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Thanks Dusko!

Well I didnt mean encryption amongst DCs in terms of replication I was
speaking in terms of AD bind authentication to work under port 636 (sldap).
The most important aspect would be secure ldap authentication.

This is a huge network, and yes I do not think it is difficult to implement
but it appears that it would seem prudent not to have it on a Domain
Controller, simply in terms of separate recovery procedures without
impacting other services on the box.

There will be no loss of money but certainly connectivity issues, if secure
ldap is required for services in which we provide. I would like sldap on all
available DCs for auth purposes.

Does this make sense?
Thanks,
Altria
"Dusko Savatovic" <nospam.savatovic@xxxxxxxxx> wrote in message
news:edcQigrVJHA.6116@xxxxxxxxxxxxxxxxxxxxxxx
Interesting question.

The answer, of course, depends on many factors.

You must asses your current infrastructure.

- What is the size of your network,
- What is the size of your company,
- What is the number of users of your service,
- Can a compromise of your CA cost you a lot of money?

When you compare the cost of potential loss and recovery of CA with the
cost of keeping this service on existing hardware or dedicated hardware,
you should reach your own decision

Some technical answers follow.

1. There is no reason why you should not install CA on a DC.

2. If you plan installing CA on a new hardware, I'd recommend Win 2008
Certificate Services. This is one component that was much improved in Win
Srv 2008.

3. For protecting network traffic between your servers in your domain, you
can use IPSec without certificates. You can use Kerberos or preshared
secret.

4. Active Directory replication traffic between DC's is already encrypted.

Conclusion
Adding CA role to a server is really not difficult.
Operating CA is not difficult.
The difficult part is keeping it safe from compromise and healthy. Also,
restoring it's functionality in case of failure or compromise.
You must have a clear policy and steps how to transfer existing CA to a
new server, what to do in case of compromise or loss of CA. This usualy
means replacing all issued certificates. Not a big deal if you have a 100
local users, but a big deal if you have 10000 users who are paying
customers and their certificates are stored on smartcards etc.


"Altria" <urbantec92@xxxxxxx> wrote in message
news:ejrlFylVJHA.4384@xxxxxxxxxxxxxxxxxxxxxxx
Hello All,
I often come across different opinions on CA installations. I have seen
that it is not recommended on a DC but I was wondering what is MS best
practice. I cannot fiind the technet article that states this. I do agree
that it should be off a DC simply becasue it is another service that
would be better off isolated, and since it requires it own
infrastructure, it should be treated as a specialized service with
dedicated hardware.

BTW, Win2k3--Ent CA for only encryption between DC's within the domain
not for clients

Any advice
thanks,
Altria





.



Relevant Pages

  • Re: Cert Authority
    ... For protecting network traffic between your servers in your domain, ... can use IPSec without certificates. ... The difficult part is keeping it safe from compromise and healthy. ... should be treated as a specialized service with dedicated hardware. ...
    (microsoft.public.windows.server.general)
  • Re: Certificate attributes for Smart Card Logon
    ... unfortunately, as far as I know if you have the "Secure Email" application Policy set, a certificate by default may not just be used for email signature but also email encryption! ... If you enable the Smart Card Logon, Client Authentication, and Secure Email application Policies, this ensure that the smart card cannot be used for actual encryption. ... My domain controllers each already have their own certificates. ...
    (microsoft.public.windows.server.security)
  • Re: Certificate attributes for Smart Card Logon
    ... signature but also email encryption! ... If you enable the Smart Card Logon, Client Authentication, and Secure ... controllers each already have their own certificates. ...
    (microsoft.public.windows.server.security)
  • Re: RECOVERING MY ENCRYPTED HD FROM DEAD WINDOWS 2000
    ... certificates were probably only stored on the reinstalled ... file encryption key - different for each file, ... document formats have some standard bytes in - once matched ... The install wouldn't ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Sending signed and encrypted email.
    ... The user may have 1 or more certificates, ... via an AD lookup, you would want their encryption certificate, not their ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... I am new to framework 2.0 so unsure about the capabilities of the ...
    (microsoft.public.dotnet.security)