proposed implementation of an Enterprise CA



I have a few questions regarding a proposed implementation of an Enterprise
CA into our production environment, which I’m hoping people can give me feed
back on. I’ve read a lot of the Microsoft documentation on PKI, however
sometimes there’s no substitute to real word experience etc.

The drive behind the need to deploy a PKI is the move to RADIUS Auth PEAP
MSCHAP v2 for our Wireless clients. I’ve successfully created a test lab
using a CISCO 1100 Series AP, and one windows 2003 enterprise server running
AD, IAS, IIS 6 & Enterprise CA. We have ruled out the purchase of 3rd party
certificates for our IAS servers and wish to deploy a PKI.

Due to our size (under one hundred users) and our modest needs to initially
improve wireless security a three tier PKI seams overkill. We can also
easily physically secure our Enterprise CA in a secure data centre.

To Outline of our environment:

All servers running Windows 2003 Enterprise with SP1, all clients winXP pro
SP2

Site 1 (Secure Data centre)
1 x Enterprise root CA (proposed location)
2 x DC
1 x Exchange server

Site 2 (Office1) Connected to Site 1 via hardware VPN
2 x IAS Server
2 x DC
50 x Wireless Users (Access 802.1x - PEAP MSCHAP v2)

Site 3 (Office 2) Connected to Site 1 via hardware VPN
2 x IAS Server
2 x DC
50 x Wireless Users (Access 802.1x - PEAP MSCHAP v2)

Questions:

1 – Will the deployment of a Enterprise CA in our production environment
require any GP changes for DC’s and clients? As I understand it a single
tier CA publishes the certs to AD.

2 – Our exchange server has a Thawte SSL cert for RPC/HTTPS and OWA access.
Can we scrape this on renewal and issue our own from our Enterprise CA?

And if so will this only work for access via domain member machines and non
domain members will be required to install a cert from us?

3 – Once the Enterprise CA has issued the cert to the IAS servers there’s no
‘continual’ traffic between the Enterprise CA and IAS servers? i.e. only if
revoked etc.

4 – I don’t need IIS on the CA as web enrolment is only needed for win2000
or non windows clients and all my clients are winXP pro SP2. Correct?

5 – A open ended question I know but any thoughts I guess - In my test lab
it was simply a case of installing the Enterprise CA, gpupdate and off I
went. Is there anything else I should be aware of when I go to production?

6 – Is the proposal sound for our needs?

If you got this far, thanks

Steve

.



Relevant Pages

  • Development and test deployment ADVICE
    ... - In one domain of the enterprise we have installed in a machine the ... and when things go right and the clients have aproved them we have to ... Make a backup of the develop portal and restore in the test portal ... of repeat the hard customization work ...
    (microsoft.public.sharepoint.portalserver.development)
  • Re: EFS and Certificate Services
    ... At this time I can reproduce the problem on a enterprise CA ... CA's should not be issuing certs to clients. ... Certificate requests the clients is requesting a EFS cert...which the ca ...
    (microsoft.public.win2000.security)
  • Exchange 2007 "smart" journaling / evolved message sorting
    ... need concerning message sorting in an exchange organization. ... Actually, in his enterprise they make great use of public folders, in ... fact it's quite common for them to "drag" mail from outlook clients to ...
    (microsoft.public.exchange.setup)
  • SAP Adapter Question
    ... Installation guide of BizTalk Adapter pack 1.0 specifies that we need to have ... have complete SAP Client version installed on BizTalk Server ... Respective enterprise application clients and associated software. ...
    (microsoft.public.biztalk.general)