IIS and enterpise sub CA on different machines



The Brain Komar texts implies that the enterprise subordinate CA (i.e.
issuing CA) needs to reside on the same machine as IIS. From a security
perspective, this seems like a poor design. From a network standpoint, it
means I have to support multiple IIS servers in my LAN.

Neither is acceptable. I would like to utilize my existing IIS server (not
on issuing CA) to provide certificate enrollment. Adding the virtual
directories seems to be pretty simple, then adding pointers from the CA to
the IIS server.

Is their anything I am missing? If someone has a good reference or web link
on how to set up using this scenario, much appreciated.


Edward W. Ray
CISSP,MCSE+Security,GCIA, GCIH


.



Relevant Pages

  • Re: IIS6 on W2k3 DCs
    ... My sister's large entity that she works at, I'm sure does not put IIS on ... >installed on a domain controller. ... >While I can protect each IIS server equally well, ... >a best security practice not to place IIS on a DC. ...
    (Focus-Microsoft)
  • Access Database Hangs Under IIS 6.0
    ... Two questions - is there an alternate method to recycle application pool space in IIS 5.0 Isolation Mode without issuing an IISRESET? ... is there an expected ETA on the Jet fix to address Access database hangs running on IIS v6.0? ...
    (microsoft.public.inetserver.iis)
  • Re: Access Database Hangs Under IIS 6.0
    ... Two questions - is there an alternate method to recycle application pool space in IIS 5.0 Isolation Mode without issuing an IISRESET? ...
    (microsoft.public.inetserver.iis)
  • RE: asp.net newbie
    ... I think the mapping was not set for asp.net 1.1 to IIS that you are running. ... You will have to map this by issuing a command at command prompt like ...
    (microsoft.public.dotnet.framework)
  • Re: Mac Server Hacked In Less Than 6 Hours
    ... Windows has RAS, and for it is built in since NT 3.1 ... | A typical IIS box and this Mac are not the same thing so the comparison ... IIS has been subject to quite a few bugs and so have ... Security isn't a proprietary attribute. ...
    (sci.crypt)