Re: Certificate

From: Keith W. McCammon (km@km.com)
Date: 03/31/03


From: "Keith W. McCammon" <km@km.com>
Date: Mon, 31 Mar 2003 11:19:14 -0500


> Is it possible to use internal CA to issue HTTPS certificates for use with
> internet facing websites?

Yes, lots of folks use this for things like Internet-based e-mail, and other
services primarily used by internal employees.

> Would I have to register my CA with verisign or someone like that?

No, although clients will receive an error that the certificate was issued
by a company that they do not trust. An effective work-around is to provide
them with a page where they can download your internal CA's certification
path. This can be done by publishing a web interface to a subordinate CA to
the Internet--just make sure you secure the CA site using basic
authentication and SSL.

--
Keith W. McCammon


Relevant Pages

  • Re: W2K3 URL to CA cannot verified!?
    ... It sounds like the clients don't have the root CA certificate in their ... reconfigured the download location to the external internet name, ... recreated the CA cert for updateing the URLs ...
    (microsoft.public.windows.server.active_directory)
  • Re: Beating Up On Microsoft...
    ... > While everyone is busy beating up on Microsoft... ... > It might be a good idea to look at the Internet as a whole. ... > Verifiable Certificate to properly identify the owner. ... > of Authentication, Encryption, etc. to protect the communication. ...
    (microsoft.public.security)
  • Re: What are the differences between the certificates *.pfx *.p12 *.cer *.crt *.spc *.p7b ??
    ... To find the latest possible Internet drafts, ... Personal Information Exchange Syntax Standard, ... 2560 X.509 Internet Public Key Infrastructure Online Certificate ...
    (comp.security.misc)
  • Re: ADFS and Certificate Services
    ... ADFS even allows you to do client certificate ... Joe Kaplan-MS MVP Directory Services Programming ... We just want to be able to give out certs to our own ... sub-CA on the internet for employees to access remotely to get certs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Outlook RPC over HTTp deosnt work
    ... If the certificate is not trusted, ... when you try to use RPC over HTTP to connect the Exchange Server. ... we don't have to manually configure RPC over HTTP. ... Make sure you have enabled "Outlook over the Internet" and "Remote Web ...
    (microsoft.public.windows.server.sbs)