Re: Certificate Server Hierchy Question

From: Rob (rob_at_nospam.com)
Date: 03/15/04


Date: Mon, 15 Mar 2004 12:12:53 -0500

David,
These references helped alot and would just like to run my setup by you. I
have small website that is going to be access by a small number, 15-20, of
users. I would like to make the site require client certificates. Since
there is such a small number of users and because the only thing the
certificate server will be used for is web certificates, I think I can just
make a 1-tier setup with one offline root ca. I will keep this server
unconnected from a network and I will manually create the certificates and
update the CRL. Does this sound ok?

Also, what's the best way to get a client certificate to a geographically
seperated user short of putting it on a disk and mailing it to them?

Thanks.

Rob

"David Cross [MS]" <dcross@online.microsoft.com> wrote in message
news:OZG$62DCEHA.3256@TK2MSFTNGP09.phx.gbl...
> These two docs should help you out:
>
> Best Practices:
>
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/maintain/operate/ws3pkibp.asp
>
>
> MSA:
>
http://www.microsoft.com/technet/itsolutions/msa/msa20rak/VMHTMLPages/VMHtm122.asp
>
>
> --
>
>
> David B. Cross [MS]
>
> --
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
> http://support.microsoft.com
>
> "Rob" <rob@nospam.com> wrote in message
> news:%23Qu8p$6BEHA.1220@TK2MSFTNGP10.phx.gbl...
> > I am trying to set up a website that will require client certificates
and
> I
> > have read through much of what Microsoft has written about Windows 2000
> > Server Certificate Server but I am a little bit unsure on the hierchy of
> the
> > servers. Any help anyone can provide would be greatly appreciated.
> >
> > From what I gather, the best setup would be to have a Standalone Root CA
> > that is not connected to the network and a Subordinate Root CA that is
> > networked. I am not really clear on why this is. What is on the Root
> that
> > you can't get from the Subordinate? Assuming that this is the
> > configuration, can the Subordinate Root be on the same server as the web
> > server? I know it's possible to do this but is it a big security risk?
> > Does IIS log certificate use so I can know who/when was accessing the
> site?
> >
> > Also, once I have this hierchy ironed out, what is the best/most secure
> way
> > to issue certificates to clients online?
> >
> > Thanks in advance.
> >
> > Rob
> >
> >
>
>



Relevant Pages

  • Re: Certificate Server Hierchy Question
    ... I think you you use an offline root CA, you will find the burden of manually ... I would like to make the site require client certificates. ... I will keep this server ...
    (microsoft.public.win2000.security)
  • Re: 2003/R2 certificate server questions
    ... been using a single openssl CA but I am looking to do a two-tier ... of machines and users that are themselves in the root. ... The last time I did this I was using Windows Server 2000 and it wasn't ... certificates, but I also want to be able to issue random certificates ...
    (microsoft.public.windows.server.security)
  • 2003/R2 certificate server questions
    ... been using a single openssl CA but I am looking to do a two-tier ... of machines and users that are themselves in the root. ... The last time I did this I was using Windows Server 2000 and it wasn't ... certificates, but I also want to be able to issue random certificates ...
    (microsoft.public.windows.server.security)
  • Re: can a microsoft enteprise Root CA be offline?
    ... > I have notice that if the CA server is offline, ... > cannot be authenticated by the IAS server. ... > Isn=3Ft it suppose that the the certificates are valid by them selfs? ... the root CA must be installed as a Standalone ...
    (microsoft.public.win2000.security)
  • Re: SSL - TS Configuration will not show installed certificates
    ... I can't tell you exactly what is going wrong with your setup, ... Request, obtain, & install cert from CA using the IIS Web Server Certificate Wizard ... We are using our own in-house CA to create an sign Certificates. ...
    (microsoft.public.windows.terminal_services)