Re: IPSEC between W2K domain member and W2K stand-alone



In article <ekgU0e#FGHA.4036@xxxxxxxxxxxxxxxxxxxx>, mvpNoSpam@xxxxxxx
says...
> a) yes
> b) any CA that is trusted for the purpose
>
> Certificates is the reasonable choice, but preshared key would also work.
>
> <justiono@xxxxxxxxx> wrote in message
> news:1137115641.613099.78800@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> > Dear All,
> >
> > I have some doubts, would you please help me to explain:
> >
> > a. Is it possible to configure IPSec communication between a W2K
> > Professional (domain member) and W2K Server (stand alone server, not
> > member of any domain).
> > b. If so, which certificate server can be used? Standalone root CA in
> > stand-alone W2K Server?
> >
> > Many thanks
> >
>
>
>
To further clarify Roger's answer. As long as both servers receive their
IPSec certificate from the same CA (or chain to the same root CA), the
certificate-based auth will work.

Standalone CA will work, but does not have to be on the standalone
server. It can be on a domain member or on a standalone CA.

Are there any other plans for digital certificates in your environment.
Try and not fall into the trap of just setting up CAs for each
application. If you see other certificate uses, plan a proper PKI before
you start setting up "pockets of PKI"

Brian
.



Relevant Pages

  • RPC over HTTP, Microsoft solution
    ... Exchange Server 2003 RPC over HTTP Deployment Scenarios ... Place a check in the box next to 'Certificate Services' and click 'Yes' ...
    (microsoft.public.exchange.setup)
  • Re: OWA 2003 w/ Smart Card Authentication.
    ... Exchange 2003 server via ActivSync. ... the IIS certificate. ... Whether or not authentication will succeed is completely dictated by ... Server's SSL certificate must be configured on root of v-server via ...
    (microsoft.public.exchange.connectivity)
  • Re: Configuring LDAP on Entourage 2004 OS X
    ... Microsoft CSS Online Newsgroup Support ... does not work with a self signed SSL certificate OR with the SSL ... configure the System to allow OMA and "Server ActiveSync" access from the ... Configuring Exchange Server 2003 for Client Access. ...
    (microsoft.public.windows.server.sbs)
  • Re: Configuring SBS2003 for OWA and RWW
    ... And make sure certificate will not be ... On the Connection Type page, click Broadband, and then click Next. ... next to Preferred DNS server and next to ... If you are using ISA, please go to ISA management console, and navigate ...
    (microsoft.public.windows.server.sbs)
  • Re: IE6 and MS Certificate Services (standalone)
    ... Flaw in Certificate Enrollment Control Could Allow Deletion of Digital ... a version mismatch between either your server or your client. ... IE6 and MS Certificate Services (standalone) ... Server:Win2000 Server with MS Certificate Services ...
    (NT-Bugtraq)