Re: Need advice for CA Model

From: John McCoy (jmccoy_at_cmatech.com)
Date: 04/30/03


Date: Wed, 30 Apr 2003 09:04:37 -0400


Thanks, that does answer that question.

"David Cross [MS]" <dcross@online.microsoft.com> wrote in message
news:ObUzLZxDDHA.2892@TK2MSFTNGP11.phx.gbl...
> The root CA must be trusted on all the clients that will enroll to the
> enterprise or subCA. If you are going to require user authentication
using
> certificates, each certificate must correspond to a user in AD with a UPN
> mapping to authenticate the user. The enterprise CA automatically creates
> this mapping, but you still need an AD account for each user.
>
> --
>
>
> David B. Cross [MS]
>
> --
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
> http://support.microsoft.com
>
> "John McCoy" <jmccoy@cmatech.com> wrote in message
> news:%23ROTx6oDDHA.3072@TK2MSFTNGP11.phx.gbl...
> > We have a customer we are setting up PKI for. We are using 2 Windows
2000
> > servers both for certificates an NT4 server with Exchange 5.5 and an NT4
> > server OWA with a certificate from a Windows 2000 CA.
> >
> > Phase one is sending and receiving digitally signed and encrypted email,
> we
> > did get that working thanks to earlier help from this group and it works
> > well with users from the inside and outside.
> >
> > The original PKI model was a Root Enterprise CA, this is being used for
> > certificates for all internal users. The second CA was a standalone
> > subordinate, this was planned to be used for issuing users from outside
> the
> > organization certificates to be used for digitally signed email. That
was
> > fine.
> >
> > The second phase is for outside vendors to be able to access the network
> via
> > VPN and digital certificate. Here is where we are in trouble. We can't
get
> > it to work.
> >
> > We plan to have them get their certificate from the standalone CA, that
> > isn't working, we get it but receive an error it can't chain back to the
> > root CA when connecting, we haven't published The root CA for security
> > cocerns, is it safe to do this? We think not.
> >
> > We then made the standalone sub a standalone root and have the same
error.
> > Also it seems we need an account in AD to connect. What is the best way
to
> > do this? Is there a good document on MS's site that explains this?
> >
> > Thanks
> >
> > John McCoy
> > jmccoy@cmatech.com
> >
> >
> >
> >
>
>



Relevant Pages

  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... we will need to have trust ... As far as standard versus enterprise, ... If the root CA is compromised your whole PKI ... > your certificates then it would make sense to use your own CA. ...
    (microsoft.public.windows.server.security)
  • Re: Standalone/ Enterprise CA issue
    ... > Subordinate Enterprise CA, running on AD ... > with standalone as Root, while Subordinate with Enterprise CA? ... Autorenew and autoenroll which certificates? ...
    (microsoft.public.security)
  • Re: Public Key on Enterprise CA
    ... 2000 or Windows Server 2003 Enterprise CA. ... I see that Verisign will sell ... > digital certificates for about $15 per user. ... > savings by managing your own subordinate CA with Verisign as the root CA ...
    (microsoft.public.win2000.security)
  • Re: Enterprise Root CA Install
    ... Thank you for your input regarding the offline CA. ... I tested the concept of creating a "standalone ... root CA" based on a Technet article entitled "Deploying ... an "Enterprise subordinate CA" installation. ...
    (microsoft.public.win2000.security)
  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... If the root CA is compromised your whole PKI is ... your certificates then it would make sense to use your own CA. ... > enterprise level certification authority. ... > and 1 or more subordinate CAs. ...
    (microsoft.public.windows.server.security)