Re: CA-SSL in IIS

From: Anthony Kim (Anthony.Kim_at_VWCREDIT.COM)
Date: 07/15/03

  • Next message: CORREIA, PATRICK: "RE: CA-SSL in IIS"
    Date: Tue, 15 Jul 2003 11:26:01 -0500
    To: focus-ms@securityfocus.com
    
    

    On Tue, Jul 15, 2003, Ed Sunder wrote:

    > What drawbacks are there in becoming your own certificate
    > service? Versus one of the major SSL services? Other than that
    > the source of the certificate (if the user looked it up) would
    > not be a commercially known provider and you couldn't
    > participate in any of the major provider's ever so valuable
    > certificate programs.
    >

    You need to maintain a strict security support structure to
    protect your certifice service servers, root CAs, intermediary
    CAs and so forth. ISS wrote up some guidelines in their MS Press
    Windows 2000 Security Technical Reference. In theory. People
    producing their own X.509 certs for private use seldom take such
    measures. But at the end of the day, how much you effort you
    should make depends on your security requirements.

    You need to distribute your root CA certficate to your users'
    browsers - so they aren't faced with the "This cert is not signed
    by a valid CA" warning. But this can be accomplished via Group
    Policy IIRC.

    Otherwise, private CA's are pretty common I reckon.

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: CORREIA, PATRICK: "RE: CA-SSL in IIS"

    Relevant Pages

    • [NT] Flaw in Outlook 2002s Way of Handling V1 Exchange Server Security Certificates Leads To Informa
      ... Beyond Security would like to welcome Tiscali World Online ... Encryption is used to prevent parties other ... Outlook uses public key certificates to facilitate the exchange of the ... there are other certificate options including V1 Exchange Server Security ...
      (Securiteam)
    • Re: Embedding Simple MFC GUI app into website
      ... particular technology is "evil" goes beyond common sense and increases ... his denouncement of ActiveX and Java (and Flash, ... ActiveX, in particular, is an antipattern for security. ... Since you must obtain a certificate for code signing from the trusted ...
      (microsoft.public.vc.mfc)
    • Re: Auto Enrollment not working for one DC
      ... Windows Server 2003 SP1 introduces enhanced default security settings for the DCOM protocol. ... Windows Server 2003 Certificate Services provides enrollment and administration services by using the DCOM protocol. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Auto Enrollment not working for one DC
      ... I was already aware of the post SP1 problem with the CERTSVC_DCOM_ACCESS ... Certificate Services: Effects of security enhancements to the DCOM protocol ...
      (microsoft.public.windows.server.active_directory)
    • Re: self-signing certificate
      ... saw that my self-signed certificate was under the ... Now warnings at all when opening with medium security set. ... And, if correct, why the warning? ...
      (microsoft.public.access.security)