CACertFileName: Chicken or Egg?

From: Dave W (DaveW_at_discussions.microsoft.com)
Date: 01/24/05


Date: Mon, 24 Jan 2005 11:39:13 -0800

I'd like to remove all DNS references from CA certificates, such that the AIA
CRT publication path is "DNS free”. As far as I can tell, including the DNS
name in the CRT name is a bit of a security poser as it reveals a CA server’s
DNS name to all and sundry.

I can easily modify the AIA paths in a post CA installation setreg command,
the problem is that the CA certificate always contains the server’s DNS name,
e.g. srv001_Company-ClientAuthCA.crt.

There is a registry value called CACertFileName that I can change to
%%3%%4.crt which in theory doesn’t include the DNS name, however, I cannot
make this registry change before the CA server is installed – and by then the
CA server’s certificate has already been published (including the DNS
reference). I could manually change the CRT filename before publishing it to
the AIA path, but this is not desired and I’m concerned that certificate
renewal will be a problem.

This is not a showstopper, but I think it would be best practice to take any
DNS server references out of a certificate’s AIA path. I particularly like
the idea that I can document CA server installation through various lifecycle
environments, e.g. poc, dev, livelike, etc. without making any explicit DNS
references.

Anyone got any ideas?

Dave



Relevant Pages

  • Re: Sorting out a FUBARed domain
    ... you will most likely either see a DNS call that comes back as unknown or an attempt to contact a machine that isn't responded to. ... Joe Richards Microsoft MVP Windows Server Directory Services ... Defending Security Infrastructures http://blog.joeware.net/2006/07/11/445/ ... I cannot find any references to any other DC's like one was just turned off and not demoted. ...
    (microsoft.public.windows.server.active_directory)
  • Re: UNC access failure: Logon Failure: The target account name is
    ... > which the ethernet cable was connected, deleted any references in DNS ... > and AD and swapped between being in a Workgroup and joining my domain ...
    (microsoft.public.win2000.dns)
  • Re: DNS Nightmare - Cant create forward zone
    ... DNS problem is soved? ... Upon rebooting the ... I have followed your instructions and removed any references to ... tmpserver - I will reboot it twice shortly. ...
    (microsoft.public.win2000.active_directory)
  • Re: DNS Trouble
    ... If you moved your dns data have you removed all references to the old dns ... AD or DNS services in your dns domain. ... I got a new server and ...
    (microsoft.public.windows.server.dns)
  • Re: Cannot request computer certificate.
    ... > request a computer certificate for about 9 months. ... > and verify that you can get a computer/server certificate from it. ... > Kerberos, or dns. ... > List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)