Simple PKI Question(s)

From: Stuart Pittwood (stuart.pittwood@blueyonder.co.uk)
Date: 11/07/02


From: "Stuart Pittwood" <stuart.pittwood@blueyonder.co.uk>
Date: Thu, 7 Nov 2002 19:41:24 -0000


Hi all,

this is my first foray into the PKI world so these questions might seem
kinda simple but I need to know if I'm getting this right and where to go
now.

If I set up a PKI using Win2k cert services and issue certificates for web
sites & email encryption (exchange 2000) then they won't be trusted by
anyone out side of our organisation? correct?

To acheive the above I would need some kind of certificate from someone like
Verisign/thawte? If so does the certificate get installed into the
certificate server which I have installed? do I need this before I install?

Would the above server be installed as an enterprise root? if it is the only
PKI server in the enterprise (the network would be all Win2k AD based)

Are there any good books that cover win2k PKI in more depth than the MS
Press Security design book?

Thanks

Stu
stu@stuartpittwood.net



Relevant Pages

  • Re: New Event Log Errors!
    ... Somehow along those lines I'd also installed the Certificate Authority ... Did you apply the last Server Pack for SBS Server? ... Please install Windows Support Tools on the win2k3 sp1 problematic ... Microsoft is providing this information only as a convenience to you: ...
    (microsoft.public.windows.server.sbs)
  • Re: Adding EXCH2007 SP1 box to existing EXCH2003 SP2 Org
    ... Certificates - going to be using a SAN Certificate like I have many times before. ... We are making this a virtual server (someone is going on-site on Thursday to install VMWare (which will kill everything on this box) and WIN2008 Server SP1 x64 and then I will install EXCH2007 SP1. ... as mentioned - ISA was not involved in any of those eight environments.... ...
    (microsoft.public.exchange.admin)
  • Re: Terminal Services over a VPN
    ... Create a certificate request and submit it to godaddy in order to obtain a public cert. ... You can use the wizard in IIS Manager for this by creating a new website that matches the above name (on your TS server), right-click and choose properties, directory security tab, server certificate button. ... After the install you can stop or delete the website created above since you don't need it for anything. ...
    (microsoft.public.windows.terminal_services)
  • Re: Outlook RPC over HTTp deosnt work
    ... Go to remote web workplace (or Outlook Web Access), accept the certificate prompt, 'view', and 'install' the certificate - accepting all the defaults. ... > when you try to use RPC over HTTP to connect the Exchange Server. ...
    (microsoft.public.windows.server.sbs)
  • Re: windows mobile 6
    ... I installed a GoDaddy certificate on the sbs server with no problem. ... The problem is that the certificate is a .crt file and my WM6 device doesnt recognise this file extention. ... The question is how do i install the certificate. ... When a computer uses RWW it downloads the certificate automatically from the server, why doesnt WM6 do the same? ...
    (microsoft.public.windows.server.sbs)