Cross Forest CA Implementation

From: Benkman (Benkman_at_discussions.microsoft.com)
Date: 10/07/04


Date: Wed, 6 Oct 2004 23:21:02 -0700

Hello,

I've got an interesting scenario that I'd appreciate any feedback on :).

Two Forests: 1 Windows 2000 (Corporate) , 1 Windows 2003 (Ecommerce)

Required: Client Certificate Authentication of an IIS 5 Server in the
Windows 2000 Forest to an IIS 6 Server in the Windows 2003 Forest.

The current intention is to create an Offline RootCA, publish this to the
Windows 2000 AD. An Windows 2000 Enterprise Subordinate in this forest would
then be comissioned for computer certs.

To meet the above approach I was considering inserting multiple LDAP CDP's
in the RootCA cert and also the subordinate cert.

We could then publish these to the Windows 2003 AD as well as the CRL's, as
required.

Thoughts or other approaches to the cross-forest conundrum?

Thanks,

Benkman.



Relevant Pages

  • Re: IIS Start up errors
    ... provide the detailed steps to reinstall the IIS server in SBS 2003 server. ... For example, programs such as Microsoft ... In the Currently installed programs list, click Windows Small Business ...
    (microsoft.public.windows.server.sbs)
  • Re: Timr service
    ... "To establish a computer running Windows Server 2003 as authoritative, ... open the 123 UDP port in my firewall and to execute on the forest PDCe: ... >> connecting to a NTP Internet server a secure solution? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory Services cannot find the web server
    ... I am having the same problem with a windows xp pro with iis 5.1 ... incedently does not work properly when connecting to the server. ... both the client and server and still no luck. ...
    (microsoft.public.dotnet.faqs)
  • Re: restated: VS Develper (non Admin) missing IIS MMC Management
    ... > debug ASP in VB.Net, and of course manage IIS MMC. ... > Microsoft Development Environment ... > Information Server on the client and the server. ... > server from a Windows NT 4.0 client. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: restated: VS Develper (non Admin) missing IIS MMC Management
    ... > debug ASP in VB.Net, and of course manage IIS MMC. ... > Microsoft Development Environment ... > Information Server on the client and the server. ... > server from a Windows NT 4.0 client. ...
    (microsoft.public.dotnet.general)