Global Repository for Externally Generated Certificates

From: Rick A. Butler (orion2634_at_yahoo.com)
Date: 07/23/04

  • Next message: Miha Pihler: "Re: Global Repository for Externally Generated Certificates"
    Date: Thu, 22 Jul 2004 18:57:22 -0600
    
    

    Hello Group!

    As part of the Department of Defense's IECA program for communications to
    DoD personnel, they DoD is moving to Certificate driven communications. As
    part of IECA, people needing to communicate with DoD will have to provision
    a Certificate from a Trusted Root Authority, such as Verisign. Currently,
    the program is not enrolling Server Certificates, so deploying an Enterprise
    CA isn't going to work for me.

    We're ordering about 200 certificates from Verisign so that we can digitally
    secure traffic for communication to DoD.

    Has anyone here ever had to deal with a massive number of certificates from
    an external CA, and what's the best practice for management, short of using
    Excel to manage them all? Is there a way to import them into sort of a
    global store that's accessible by all and that will allow me to also do
    revokations?

    My network is a Windows 2000 Native Active Directory, with MS Exchange 2000
    as my principle messaging platform.

    Thanks in Advance -

    Rick Butler


  • Next message: Miha Pihler: "Re: Global Repository for Externally Generated Certificates"

    Relevant Pages

    • Re: Global Repository for Externally Generated Certificates
      ... enterprise CA to that organizations could manage their own certificates. ... >> DoD personnel, they DoD is moving to Certificate driven communications. ...
      (microsoft.public.windows.server.security)
    • Re: Global Repository for Externally Generated Certificates
      ... sine you are not the one issuing certificates, you won't be able to revoke ... If you order them from Verisign, they are the only one that can revoke ... > DoD personnel, they DoD is moving to Certificate driven communications. ...
      (microsoft.public.windows.server.security)
    • Re: Restricting file server to access to domain computers only.
      ... implement a domain-wide IPSec policy ... PSK or certificates, for the authentication method. ... authenticate communications is up to you. ... > system they are connecting from is a member of the ...
      (Focus-Microsoft)
    • Only show "identify" certificates.
      ... Need help with possibly IIS configuration. ... As you know there are usually multiple client certificates on a DoD CAC ...
      (microsoft.public.inetserver.iis.security)
    • Only show Identity certificates
      ... Need help with possibly IIS configuration. ... As you know there are usually multiple client certificates on a DoD CAC ...
      (microsoft.public.inetserver.iis.security)