Certificate Server Hierchy Question

From: Rob (rob_at_nospam.com)
Date: 03/11/04


Date: Thu, 11 Mar 2004 16:29:17 -0500

I am trying to set up a website that will require client certificates and I
have read through much of what Microsoft has written about Windows 2000
Server Certificate Server but I am a little bit unsure on the hierchy of the
servers. Any help anyone can provide would be greatly appreciated.

>From what I gather, the best setup would be to have a Standalone Root CA
that is not connected to the network and a Subordinate Root CA that is
networked. I am not really clear on why this is. What is on the Root that
you can't get from the Subordinate? Assuming that this is the
configuration, can the Subordinate Root be on the same server as the web
server? I know it's possible to do this but is it a big security risk?
Does IIS log certificate use so I can know who/when was accessing the site?

Also, once I have this hierchy ironed out, what is the best/most secure way
to issue certificates to clients online?

Thanks in advance.

Rob



Relevant Pages

  • Re: copy files from internet using authenticate certificates
    ... Just use ASP.NET on the server, configure your IIS server to use SSL and ... require client certificates. ... you'll need some kind of software that runs when the laptop ... > How I need to use these certificates is the confusing part. ...
    (microsoft.public.dotnet.general)
  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • RE: L2TP/IPSEC site-to-site question
    ... seems more difficult on Windows and Isa 2000 mix, ... If I want to use certificates what type I have to use? ... > site-to-site VPN connection. ... > Site-to-Site VPN in ISA Server 2004 ...
    (microsoft.public.isa)
  • Re: Vista wireless using IAS and WPA-Enterprise
    ... certificates, which may be more than the limit that the IAS server can send ... on a Web site or if you use IAS in Windows Server 2003 ... Vista wireless using IAS and WPA-Enterprise ...
    (microsoft.public.windows.server.networking)
  • Re: Certificate Server Hierchy Question
    ... > have read through much of what Microsoft has written about Windows 2000> Server Certificate Server but I am a little bit unsure on the hierchy of the> servers. ... the best setup would be to have a Standalone Root CA> that is not connected to the network and a Subordinate Root CA that is> networked. ... Assuming that this is the> configuration, can the Subordinate Root be on the same server as the web> server? ... > Also, once I have this hierchy ironed out, what is the best/most secure way> to issue certificates to clients online? ...
    (microsoft.public.win2000.security)