Certificate Requirements for SQL Data Encryption



We are in the process of attempting to issue certificates from our
Enterprise CA to use in SQL encryption. I can not find documented anywhere
what the key attribute requirements are (Key Usage and Application Policies,
etc.) for the Certificates. I understand that SQL Server can issue it's own
certificates, but for management and consistency, we would like to issue
them from our Enterprise CA.

Could someone point me to this documentation?

Thanks!

Jediah L.


.



Relevant Pages

  • Re: 2003/R2 certificate server questions
    ... running OPenSSL to service requests from Linux/samba ... certificates, but I also want to be able to issue random certificates ... Make sure you are running on Enterprise Edition, ... Automatic certs, Key archival and recovery, customizable ...
    (microsoft.public.windows.server.security)
  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... we will need to have trust ... As far as standard versus enterprise, ... If the root CA is compromised your whole PKI ... > your certificates then it would make sense to use your own CA. ...
    (microsoft.public.windows.server.security)
  • Re: client user certificates
    ... in certificates using Windows Server 2003 Enterprise Edition Enterprise CAs ... but it would be nice if there was a way to autoenroll the user. ... We have a Windows Server 2003 domain environment with a Enterprise ...
    (microsoft.public.windows.server.active_directory)
  • RE: CA Client Certificates only expire in one years time
    ... If this was installed as an Enterprise CA this is normal. ... which in v1 templates cannot be modified. ... "For certificates that are issued by Enterprise CAs, the validity period is ...
    (microsoft.public.windows.server.general)
  • EFS certificate renewal
    ... We use EFS in our organization and have a Windows 2003 Enterprise CA ... If the computer is not connected when the renewal period is first ... If the first renewal request is not successful because the Enterprise CA ... certificates, ...
    (microsoft.public.win2000.general)