Digital Certificates

From: Tony Su (anonymous_at_discussions.microsoft.com)
Date: 05/13/04


Date: Thu, 13 May 2004 06:19:12 -0700


>From what I've seen, I don't see how the certificates
generated by the CEICW can be verified (although maybe
someone might describe something I've missed).

Consider what purpose you wish to use your certificates.
If you wish to secure email, you only need to issue
certificates, you do not need to publicly verify the
certificate, it's a private mutual exchange of
certificates between the two parties only.

If you want to set yourself up as a public CA where you
verify the identity of a webserver or client through PKI,
you will probably need to install Certificate Server,
publish it and modify the entry which describes how your
Certificate Server is to be identified on the Internet.

I describe how to install Certificate Server in my "Web
Publishing Companyweb" paper so you can issue any number
of certificates for any need you might have.

You would also publish your CA by either modifying your
OwA Web Publishing Rule or creating a new rule.

The instructions for modifying your CA for its Internet
name is in the help files and KB.

If your Users are configured to trust your private CA,
they will not see the popup warnings you often see today
in SBS (which, by the way IMO is a serious security issue
people are not paying enough attention to).

Tony Su

>-----Original Message-----
>I've been asked by one of our users if it's possible to
have a digital
>certificate without paying for it. I know it will be
untrusted and will
>prompt people because of that and have warned him of this.
>
>I've had a look at the certificates bit on the server and
have figured out
>issuing certificates. My question is how do I make the
verification service
>available over the net, so that if people choose to trust
the issuing
>authority the authenticity of a certificate can be
verified?
>
>Running SBS 2003 Premium with ISA installed.
>
>Thanks for any assistance you can give me.
>
>
>
>Adam
>
>
>.
>



Relevant Pages

  • Re: Slightly OT: SSL certs - best practice?
    ... Thus, I have created several certificates for Apache SSL hosts plus certificates for mail serving, etc. ... I'll probably get some "officially" signed certs. ... certificates signed by a CA that does not do a "real" verification of the requesting person by which I mean that you probably don't need to go somewhere and show some official ID to prove that you are in fact you. ... using an anon "class 1" root. ...
    (FreeBSD-Security)
  • Unknown (garbled name) certificates shown as invalid - Are they safe?
    ... I noticed under the "Certificates - Current User -> ... REQUEST -> Certificates" node that about a dozen certificates were ... Can I delete these supposedly invalid certificates? ... verified (because Outlook has problems with verification if the CA ...
    (microsoft.public.win2000.security)
  • RE: Windows Update : Error number: 0x80096005
    ... Certificates issues! ... We have a certificate server installed on site and the problem was related ... [ClientId = WindowsUpdate] ...
    (microsoft.public.windows.server.general)
  • Re: wireless network disconnects when using IEEE 802.1x authentication
    ... server, a certificate server, and computer and user certificates. ... > I have a Blitzz 108 mb Super G Firewall Router and wireless adapter I ...
    (microsoft.public.windowsxp.security_admin)
  • Re: OWA security question with Exchange 2007
    ... MVP - Exchange ... like to do is leverage our certificate server that we currently have to ... secure OWA on exchange 2007. ... Verisign certificates, what are the pros and cons in using our own ...
    (microsoft.public.exchange.setup)