RE: Issue Certificate to AD Users

From: Dmitrii Zakharov[MSFT] (dmitriiz_at_online.microsoft.com)
Date: 04/05/04


Date: Sun, 4 Apr 2004 23:21:05 -0700

Hi, Allie,
x509 certificates are not directly associated with Active Directory. They
are issued to so called Common Name (CN). However, an AD user, logged into
windows, can install his certificate to CurrentUser system store. That way
programs running in his logon session will have access to his certificate
and will use it for establishing SSL connection.

In addition, you can use Active Directory to establish explicit mapping of a
certificate to domain account. (Ask if you need more details on exact
procedure). In that case such a certificate should be stored at Domain
Controller.

Now, what about issuing certificates, you will have to install Certificate Authority (CA) on your server.
(To do that you will have to go to Add-Remove programs -> Add Windows Components -> Certificate Services).
(Then you will go to run --> mmc --> add snap-in, and choose CA). CA has help that should be sufficient for issuing
certificates.

-Dmitrii



Relevant Pages

  • RE: updates after format
    ... if the Microsoft Server is down. ... software you are installing has not passed Windows Logo testing verify its ... When you try to download an ActiveX control, install an update to Windows ... and you do not have the appropriate certificate in your Trusted Publishers ...
    (microsoft.public.windows.mediacenter)
  • Re: Windows Update repeats
    ... You cannot install some updates or programs ... to a Windows component, install a service pack for Windows or for a Windows ... The Microsoft digital signature affirms that software has been tested with ... Publishers certificate store. ...
    (microsoft.public.windowsupdate)
  • Cannot Manage Certificate Services error message
    ... I’m currently practicing installing Windows 2003 Certificate Service, ... were correct and the DC and issuing CA server could see each other. ... script that I ran during the post install on the root CA. ...
    (microsoft.public.windows.server.security)
  • Problems Installing Win2K3 Cert services
    ... I’m currently practicing installing Windows 2003 Certificate Service, ... were correct and the DC and issuing CA server could see each other. ... script that I ran during the post install on the root CA. ...
    (microsoft.public.security)
  • Re: windows updates not running
    ... >Windows Updates on XP? ... When you try to install a package from the Windows Update Web site you ... Attempt to download and install Windows Updates again, ... "NOLIABILITY ACCEPTED, 97 VeriSign, Inc." certificate under Trusted ...
    (microsoft.public.windowsxp.help_and_support)

Loading