Re: Certificate Issuing

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



John F Kappler wrote:
Another question...

The internet is connected to our server by two ADSL lines (through a
load balancing router), each with its own static ip address.

I'm arranging for two A records to be setup: reca.mydomain.com and
recb.mydomain.com to address each of the ips so that remote users can
choose which line they connect through.

I presume I cannot set up two certificates using CEICW so I'll choose
reca.

If the user installs that cert on their PC, does it matter which
connection they then elect to use?


Not too much. The point of the certificate is so that the browser
warns the user if the certificate FQDN does not match the URL of
the connection, and this would happen here if they connect to the
'other' one. As long as they are happy to check they have a correct
URL and hit 'go ahead anyway' there's not a problem.

This is the underlying reason for using traceable certificates.
There's nothing to stop you asking a self-signed CA for a web server
certificate for 'microsoft.com', but a commercial certification
authority will make at least a token check to see if a customer
actually has the right to the domain name. This work is part of what
you're paying for, and is irrelevant within a single company.
.



Relevant Pages

  • RE: L2TP/IPSEC site-to-site question
    ... seems more difficult on Windows and Isa 2000 mix, ... If I want to use certificates what type I have to use? ... > site-to-site VPN connection. ... > Site-to-Site VPN in ISA Server 2004 ...
    (microsoft.public.isa)
  • RE: L2TP/IPSEC site-to-site question
    ... Microsoft Internet Security and Acceleration (ISA) Server 2004 ... >site-to-site vpn connection. ... >My concerns are about the certificates part. ...
    (microsoft.public.isa)
  • L2TP/IPSEC site-to-site question
    ... My main site is using a Windows 2000 server with ISa 2000, ... and with this type of connnection I am able to make the connection ... My concerns are about the certificates part. ...
    (microsoft.public.isa)
  • L2TP/IPsec sites-to-sites vpn
    ... My main site is using a Windows 2000 server with ISa 2000, ... and with this type of connnection I am able to make the connection ... My concerns are about the certificates part. ...
    (microsoft.public.security)
  • Re: schannel failure between AD CA and NT Domain
    ... The CA is showing up in the Trusted Root Certification Authorities Tab, ... Also each server has personal certificates as well. ... >> connection to the retrieve info. ...
    (microsoft.public.win2000.security)