Re: can a microsoft enteprise Root CA be offline?

From: Brian Komar (bkomar_at_nospam.identit.ca)
Date: 10/26/04


Date: Tue, 26 Oct 2004 14:39:42 -0500

In article <d51193cc.0410260952.50d69cc9@posting.google.com>,
izael.ochoa@reforma.com says...
> Hi everyone, sorry my english
>
> Does anyone know if a microsoft enterprise root certification
> authority can be offline?
>
> I have notice that if the CA server is offline, the EAP-TLS clients
> cannot be authenticated by the IAS server.
>
> Isn=3Ft it suppose that the the certificates are valid by them selfs?
> why does the CA needs to be available in order to the certificates be
> authenticated?, is there any redundancy squeme that could be used?, if
> the Ca server fails, nobody would be able to acces the network
>
> thaks in advance
>
No. To be an offline CA, the root CA must be installed as a Standalone
Root CA. Please see the best practices whitepaper:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/maintain/
operate/ws3pkibp.asp

Brian



Relevant Pages

  • Re: Certificate Server Hierchy Question
    ... I think you you use an offline root CA, you will find the burden of manually ... I would like to make the site require client certificates. ... I will keep this server ...
    (microsoft.public.win2000.security)
  • Re: Certificate Server Hierchy Question
    ... These references helped alot and would just like to run my setup by you. ... I would like to make the site require client certificates. ... I will keep this server ... the best setup would be to have a Standalone Root CA ...
    (microsoft.public.win2000.security)
  • RE: Offline Root CA issue
    ... I had to change the validity of the CRL ... subordinate online CA server in an Windows 2003 Server environment (virtual ... I have exported the CRL from the offline root into the online ...
    (microsoft.public.dotnet.security)
  • Re: CA Troubles
    ... > Services in a Windows 2003 Server environment (Offline Root and Online ... The revocation function was unable to check revocation ...
    (microsoft.public.windows.server.security)
  • Re: 2003/R2 certificate server questions
    ... been using a single openssl CA but I am looking to do a two-tier ... of machines and users that are themselves in the root. ... The last time I did this I was using Windows Server 2000 and it wasn't ... certificates, but I also want to be able to issue random certificates ...
    (microsoft.public.windows.server.security)