Shared Certificate Store in Active Directory

From: Steve Buckley (anonymous_at_discussions.microsoft.com)
Date: 12/24/03

  • Next message: Stan: "urgent help needed with inet.bat file"
    Date: Wed, 24 Dec 2003 14:42:21 -0800
    
    

    WARNING - This question is not as easy as it may first
    seem, this is a repost of a question originally asked in
    the Active Directory forum.

    How do you configure a "Shared Certificate Store" in
    Active Directory so you can make Certificates and their
    associated Public Keys available to members of the
    Enterprise, for example to enable IPSec encryption using
    Certificates rather than Kerberos?

    They are clearly stored *somewhere* already as they are
    visible against the user/machine accounts in the Active
    Directory Users & Computers MMC.
    The CDP container only contains the CRL object - where is
    the actual store and how do you set permissions on it?
    Or do you have to create one somehow?

    I have been puzzeling over this one for a good 6 months -
    if someone comes back to me with click on "Allow
    certificates to be published in Active Directory" I'll
    slap them for not reading my question.
    .

    The answer to this question does not appear to be in any
    of the Microsoft Security MCSE core texts or Technet.


  • Next message: Stan: "urgent help needed with inet.bat file"

    Relevant Pages

    • Re: Encrypted emails
      ... Your Problem is the availability of the Certificates. ... the public keys you can send them encrypted mails. ... many MUAs to send the public key with signed mails. ... I have a CA in my windows 2000 active directory domain and my users are able ...
      (Security-Basics)
    • Re: Enterprise Certificate Authority question
      ... be to try removing the certificates on one domain controller first - not the ... change in Active Directory such as creating a new user on a different domain ... >> Publishers group which would show the actual server names of computers ...
      (microsoft.public.win2000.security)
    • Re: Question on autoenrollment process with revoked certificate.
      ... "Autoenrollment deletes expired and revoked certificates in the ... userCertificate attribute on the user object in Active Directory. ...
      (microsoft.public.security)
    • RE: SSL configuration for SQL server
      ... There are basically three methods for getting the certificates ... Using web request to a StandAlone CA without Active Directory. ... 324777 Support WebCast: Microsoft SQL Server 2000: How to Configure SSL ...
      (microsoft.public.sqlserver.security)
    • Re: Enterprise Certificate Authority question
      ... Active Directory does not require CA service. ... If you setup enterprise CA (CA service that integrates with active ... If such certificates were issued to domain controllers, ...
      (microsoft.public.win2000.security)