Re: PKI Question

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 10/07/05


Date: Fri, 7 Oct 2005 19:06:57 +1000


"Best practice" for enterprise doesn't always apply to small site/small
business situation. I believe you can run a single root/issuing CA and
secure that.

-- 
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
"Russ Allen" <RussAllen@discussions.microsoft.com> wrote in message
news:91F25D01-F084-4288-9CD9-23E84D90DCB7@microsoft.com...
> I am in charge of a PKI Enterprise Root CA that issues out certs for a ift
> certificate site automatically and I was presented with taking off the
Root
> CA and putting in two subordinate CAs. We run the Root CA on a VM and it
is
> not going to be very secure (andyone can log on to the server powerup the
VM
> and log on and do their thing) I think we are making this over cmplicated,
we
> only service that one site  and it has been running smooth for several
years.
> It was stated the 2 tiers was the best practice but I don't feel we need
to
> do that just one Sub CA if any a bit of wisdom is requeted from this fine
> community. thanks in advance.
>
> Russ Allen


Relevant Pages

  • Re: Special considerations with SBS2003 for CPAs, lawyers, medical, e
    ... Just yesterday a fellow CPA sent me, another CPA a pdf of a tax form with SSN numbers unencrypted. ... You first need to educate us on secure practices of handling data. ... You'd have to consult with an attorney, but in my mind, unless your client informs you of their legal requirements, or you hold yourself out to be a consultant that makes someone Hipaa compliant, the legal liability is on the back of that client. ... Good practice is how do you want YOUR personal information handled. ...
    (microsoft.public.windows.server.sbs)
  • Re: Place holder root domain advantage
    ... Old best practice said to not use your ... routeable internet domain name as the domain for your forest root domain. ... it as simple as possible with as few domains as your enterprise can ... What are the underlying reasons why the place holder root domain is ...
    (microsoft.public.windows.server.active_directory)
  • RE: Windows XP Services Best Practice
    ... It is certainly secure; ... Windows XP Services Best Practice ... services should be "disabled" on enterprise desktops according to ... Try http://www.nsa.gov/snac/ - NSA's security configuration guides. ...
    (Focus-Microsoft)
  • Re: Active System Segment needs replacing
    ...  Since the SYSSEG ... is in use all the time I am wondering the best practice to replace it.. ... I could secure it "AAAA" but that kinda defeats the security of the ...
    (comp.sys.tandem)
  • Re: [Full-disclosure] Major Greek bank sites with SSL vulnerable to XSS and open redirects
    ... cute opinion, but fairly useless in practice. ... was secure by default" or similar failure. ...
    (Full-Disclosure)