Re: CA - Certificate Authority for Authentication?



Hi,

Yes, you can use CA to deploy user certificate in combination with e.g.
smart cards and then only allow (remote) logons to server using these smart
cards...

Here are some white papers on how to set up CA server

Here are some articles on how to set up Microsoft CA and how to deploy
certificates to users.

Best Practices for Implementing a Microsoft Windows Server2003 Public Key
Infrastructure
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx

Implementing and Administering Certificate Templates in Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03crtm.mspx

PKI Enhancements in Windows XP Professional and Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/winxppro/plan/pkienh.mspx

Windows Server 2003 PKI Operations Guide
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03pkog.mspx

Managing a Windows Server 2003 Public Key Infrastructure
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/mngpki.mspx

Advanced Certificate Enrollment and Management
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/advcert.mspx

You can use Smart Card for remote logons to domain, terminal servers, VPN,
web servers, etc.
You can also use certificates stored on local hard drive to logon to web
servers.

I hope this helps you out. Feel free to post back with any additional
questions.

--
Mike
Microsoft MVP - Windows Security

"'puter-rooter" <puterrooter@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:CD760703-17DB-4E6A-A6E0-F971D8DC4FBF@xxxxxxxxxxxxxxxx
Can a CA be used to authenticate remote users?
Specifically, can a user be set up to have / use a certificate in order to
gain access to a remote network?

My understanding is that you could use a corporate CA to generate a
certificate, and use the certificate as part of a Token / Smart Card /
other
form of authentication.

If this is possible, can someone point me to some site that will give more
information / or outline the procedure?

I've been told that it can be done, and that it can't be done (CA's aren't
used for this kind of purpose)... I think it can be - but want to know for
sure.

Thanks in advance!
Mike H.


.



Relevant Pages

  • Re: How to create signed crypto message (p7m)
    ... How do I use MS Win32 CryptoAPI to compose PKCS#7 ... certificate with public key? ... Key pair is inside smart card. ... server and accessible for read/sign via web application. ...
    (microsoft.public.platformsdk.security)
  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Certificate Templates - Duplicating template - Issue does not work
    ... Enterprise Edition if you need to modify your certificate templates. ... Implementing and Administering Certificate Templates in Windows Server 2003 ...
    (microsoft.public.win2000.security)
  • RE: Problems enabling smart card login on windows 2000
    ... Bad Certificate; ... Troubleshooting Windows 2000 PKI Deployment and Smart Card Logon ... | - Installing a Windows 2000 Server as a Domain Controller ...
    (microsoft.public.win2000.security)