Re: installing an offline root CA

From: Miha Pihler [MVP] (mihap-news_at_atlantis.si)
Date: 01/18/05


Date: Tue, 18 Jan 2005 21:27:02 +0100

I believe this article should help you out...

How to import third-party certification authority (CA) certificates into the
Enterprise NTAuth store
http://support.microsoft.com/kb/295663/EN-US/

*****
More resouces on the subject of PKI

Windows Server 2003 PKI Operations Guide
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03pkog.mspx

Managing a Windows Server 2003 Public Key Infrastructure
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/mngpki.mspx

Best Practices for Implementing a Microsoft Windows Server 2003 Public Key
Infrastructure
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx

PKI Enhancements in Windows XP Professional and Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/winxppro/plan/pkienh.mspx

Encrypting File System in Windows XP and Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx

Implementing and Administering Certificate Templates in Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03crtm.mspx

Certificate Autoenrollment in Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx

Advanced Certificate Enrollment and Management
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/advcert.mspx

Key Archival and Management in Windows Server 2003
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/kyacws03.mspx

Configuring and Troubleshooting Windows 2000 and Windows Server 2003
Certificate Services Web Enrollment
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx

Troubleshooting Certificate Status and Revocation
http://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx

-- 
Mike
Microsoft MVP - Windows Security
"bill" <bill@discussions.microsoft.com> wrote in message 
news:89E2F0D5-DB85-4FDE-97A1-D441E27352E7@microsoft.com...
> i am trying to follow the how to article # 271386 for installing an 
> offline
> root CA but i am using server 2003, i'm stuck on the dsstore utility. i 
> can't
> seem to find it online, do i have to buy the resource kit for 2000? would 
> it
> still work on server 2003? is there another tool or method to publish my 
> root
> certificate and the crl to active directory? 


Relevant Pages

  • Re: GPG
    ... http://www.garlic.com/~lynn/aadsm8.htm#softpki19 DNSSEC ... http://www.garlic.com/~lynn/aadsm12.htm#53 TTPs & AADS Was: First Data Unit Says It's Untangling Authentication ... http://www.garlic.com/~lynn/2002i.html#67 Does Diffie-Hellman schema belong to Public Key schema family? ... http://www.garlic.com/~lynn/2004p.html#60 Single User: Password or Certificate ...
    (comp.os.linux.security)
  • Re: WPA and Microsoft PKI considerations in a NT4 Domain environment
    ... > Is it possible to implement a domain member Microsoft Windows Server ... > Microsoft PKI before we upgrade to a 2003 Active Directory Domain? ... Keep in mind that how you configure your certificates in Certificate ...
    (microsoft.public.windows.server.networking)
  • Re: What to do with certificates when profile is deleted/recreated?
    ... Best Practices for implementing Windows Server 2003 PKI: ... Troubleshooting Certificate Status and Revocation whitepaper: ... Windows Server 2003 web enrollment and troubleshooting guide: ... roaming user profiles ...
    (microsoft.public.windows.server.security)
  • Re: Isolation of the Root CA
    ... Windows Server 2003 web enrollment and troubleshooting guide: ... Best Practices for implementing Windows Server 2003 PKI: ... Troubleshooting Certificate Status and Revocation whitepaper: ... >>> standalone root CA and use it to issue a certificate for an Enterprise ...
    (microsoft.public.win2000.security)
  • Re: installing an offline root CA
    ... what about the CRL? ... > Managing a Windows Server 2003 Public Key Infrastructure ... > Best Practices for Implementing a Microsoft Windows Server 2003 Public Key ... > Implementing and Administering Certificate Templates in Windows Server 2003 ...
    (microsoft.public.security)