Re: Certificate Authority How-to Question

From: David Cross [MS] (vaq130@hotmail.com)
Date: 08/11/02


From: "David Cross [MS]" <vaq130@hotmail.com>
Date: Sat, 10 Aug 2002 16:26:06 -0700


The CA never generates the keys, it should never generate the keys.

Just generate the cert from a client and then export into PKCS #12 format
(*.pfx file) and then import into your VPN client.

--
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
http://support.microsoft.com
"Marvin Adeff" <madeff@tams.com> wrote in message
news:158001c23d9a$f8596020$3bef2ecf@TKMSFTNGXA10...
> Does anyone know how to get Win2K CA to issue both a
> Private and Public Cert so I can install them on my
> hardware IPSec VPN boxes?  I have a central box that I
> assume would get the Private Cert.  And then the outside
> boxes would get the Public Certs.
>
> I cannot find CA documentation that makes this
> understandable.  Any help would be appreciated.
>
> Marvin


Relevant Pages

  • Re: IPSEC interoperability with Win2K client?
    ... static-configured keys). ... W2k don't support aggresive mode negotiation ... use latest racoon and FreeBSD 4.5-STABLE ... W2k station key and cert add to ...
    (FreeBSD-Security)
  • Re: Questions (Rants?) About IPSEC
    ... in which case you have no certificates and a single secret key ... Pre-shared keys are not necesarily ... > If you start a session, the remote party (racoon) sends its cert. ...
    (FreeBSD-Security)
  • Re: decrypt files
    ... will now have to start re-creating the files I lost. ... encryption feature is very easy to use and EXTREMELY ... If keys are stored ... >> associated with the Cert and I ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS, Recovery Agent, Lost CERTs, same user.....HELP PLEASE!
    ... > You can not recreate the keys, ... > If you do not have the originals, your data is as good as gone. ... I'm guess mkaing a new CERT ... >> on ym user profile or sometin from XP but i have no idea how to do this. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS, Recovery Agent, Lost CERTs, same user.....HELP PLEASE!
    ... > You can not recreate the keys, ... > If you do not have the originals, your data is as good as gone. ... I'm guess mkaing a new CERT ... >> on ym user profile or sometin from XP but i have no idea how to do this. ...
    (microsoft.public.windowsxp.security_admin)