Re: PKI design

From: David Cross [MS] (dcross@online.microsoft.com)
Date: 10/20/02


From: "David Cross [MS]" <dcross@online.microsoft.com>
Date: Sat, 19 Oct 2002 15:48:00 -0700


Well, this gets a little complex. You can set this up in a simple way by
creating an enterprise root CA and enrolling your users and servers for
appropriate certs. Your "external users" will have to trust this root
certificate when sending e-mail or visiting your secure web sites like OWA.
This is a manual process for individual users - this is the hardest issue to
cope with. Next, users will have to "exchange" their encryption certs with
external users so mail can be encrypted - this is also a manual process.

This whitepaper will help you understand how trust is built with root certs:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechn
ol/winxppro/support/tshtcrl.asp

--
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
http://support.microsoft.com
"John McCoy" <jmccoy@cmatech.com> wrote in message
news:OqRithudCHA.1700@tkmsftngp10...
> I have a quick question, if I create a root CA in my domain is this a good
> choice for users to be able to retrive secure email via OWA? Or should I
set
> up the server up differently?
>
> I also want outside people to send and receive secure email from the users
> inside.
>
> Thanks
>
> John
>
>


Relevant Pages

  • Re: Restricting access to a web server by IP
    ... > remote control clients, etc - we remotely ... > The agrument against is that mpst vulnerabilities seem to come through ... > servers, and blocking access to all IPs accept those on the allowed list - ...
    (comp.security.misc)
  • Re: Restricting access to a web server by IP
    ... > remote control clients, etc - we remotely ... > The agrument against is that mpst vulnerabilities seem to come through ... > servers, and blocking access to all IPs accept those on the allowed list - ...
    (comp.security.firewalls)
  • Re: Restricting access to a web server by IP
    ... > remote control clients, etc - we remotely ... > The agrument against is that mpst vulnerabilities seem to come through ... > servers, and blocking access to all IPs accept those on the allowed list - ...
    (alt.computer.security)
  • Re: Forest to Child -- Permissions
    ... My account can login to all the DCs and has full administrator priv. ... first DC in the root. ... the member servers only ... never happen unless some admin has been mucking about. ...
    (microsoft.public.windows.server.dns)
  • Re: United States Says No! Internet is Ours!
    ... > "The internet is controlled to a large extent by the 'root servers'; ... the set of root name servers. ... > make an annual extortion payment required by ICANN which goes to fund ... > ICANN _could_ have written contracts for users with some protections ...
    (comp.dcom.telecom)

Quantcast