Re: Securing a Web Enrollment Server

From: Eric Chamberlain (eric.chamberlain_at_newsgroups.nospam)
Date: 05/06/04


Date: Wed, 5 May 2004 17:56:56 -0700


"Max" <maxroberts1@yahoo.com> wrote in message
news:3a37fa17.0405051325.60fd4741@posting.google.com...
> We're in the designing phase for a Windows 2003 PKI. We plan to
> separate the Web Enrollment IIS server from the Issuing CA. Is this
> good practice?
>
I think it is a good idea to separate the functions, especially if your
users are connecting remotely and requesting certificates.

> Furthermore, is there any security reason not to host the Web
> Enrollment server on the web farm, or is there reason to host it on a
> dedicated server?
>

We host our RA in a web farm. The only issue I can think of is if you need
to trust the machine for delegation, other sites would also be trusted for
delegation.



Relevant Pages

  • Re: Constrained delegation question!
    ... remote server running the services in terms of the security audits on the ... AUTHORITY\ANONYMOUS LOGON event. ... you won't be able to get Kerb delegation to ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Unix Bind and Windows DNS coexist problem with forwarder ON
    ... not a web server. ... Here is the MS KB link of how i setup in Microsoft DNS server. ... I setup delegation in UNIX BIND server to Windows 2003 ... >>> The above does not describe delegation. ...
    (microsoft.public.windows.server.dns)
  • Re: Constrained delegation question!
    ... You are right there is a service called HOST on the target server which I ... You should not need to create a new SPN though. ... Active Directory under the delegation tab, ... For allowing Service Control Manager, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Constrained delegation question!
    ... You are right there is a service called HOST on the target server which I ... You should not need to create a new SPN though. ... Active Directory under the delegation tab, ... For allowing Service Control Manager, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: PROBLEM: ASP on IIS 5 secured via "Windows Integrated Authentication" accessing "
    ... I have two virtual directories on same server with Integrated ... If i use basic authentication, ... as .NET framework config file) as well as Delegation as specified by the ... > could do whatever you want in your ASP page on behalf of the Domain Admin. ...
    (microsoft.public.inetserver.iis.security)

Quantcast