can a microsoft enteprise Root CA be offline?

From: izael (izael.ochoa_at_reforma.com)
Date: 10/26/04


Date: 26 Oct 2004 10:52:36 -0700

Hi everyone, sorry my english

Does anyone know if a microsoft enterprise root certification
authority can be offline?

I have notice that if the CA server is offline, the EAP-TLS clients
cannot be authenticated by the IAS server.

Isnīt it suppose that the the certificates are valid by them selfs?
why does the CA needs to be available in order to the certificates be
authenticated?, is there any redundancy squeme that could be used?, if
the Ca server fails, nobody would be able to acces the network

thaks in advance



Relevant Pages

  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • RE: L2TP/IPSEC site-to-site question
    ... seems more difficult on Windows and Isa 2000 mix, ... If I want to use certificates what type I have to use? ... > site-to-site VPN connection. ... > Site-to-Site VPN in ISA Server 2004 ...
    (microsoft.public.isa)
  • Re: Vista wireless using IAS and WPA-Enterprise
    ... certificates, which may be more than the limit that the IAS server can send ... on a Web site or if you use IAS in Windows Server 2003 ... Vista wireless using IAS and WPA-Enterprise ...
    (microsoft.public.windows.server.networking)
  • RE: L2TP/IPSEC site-to-site question
    ... Microsoft Internet Security and Acceleration (ISA) Server 2004 ... >site-to-site vpn connection. ... >My concerns are about the certificates part. ...
    (microsoft.public.isa)
  • Re: IAS EAP (PEAP)
    ... > IAS is registered with AD so I am okay there. ... If you create the server cert using the information below, ... Use this procedure to configure IAS server certificates for use with PEAP ...
    (microsoft.public.internet.radius)

Quantcast