Concealment of DNS Name in CA Certificate

From: Dave W (DaveW_at_discussions.microsoft.com)
Date: 01/30/05


Date: Sun, 30 Jan 2005 00:11:01 -0800

I'd like to remove all DNS references from CA certificates, ­such that the
AIA CRT publication path is "DNS free". As far as I can­ tell, including the
DNS name in the CRT name is a bit of a security poser as it reveals a CA
server's DNS name to all and sundry.

There is a registry value called CACertFileName that I can c­hange,
how­ever, I cannot make this registry change before the CA server is
ins­talled - and by then the CA server's certificate has already been
pub­lished (including the DNS reference). I could manually change the ­CRT
filename once published, but this will cause me problems when I come to
certificate renewal.

Anyone got any ideas?

Dave



Relevant Pages

  • Re: Cannot request computer certificate.
    ... > request a computer certificate for about 9 months. ... > and verify that you can get a computer/server certificate from it. ... > Kerberos, or dns. ... > List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)
  • Re: Cannot request computer certificate.
    ... >problem since you can not request a certificate while logged onto the CA. ... Verify that you can ping it by name and IP address from the client ... >> Kerberos, or dns. ... >> List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)
  • Re: Cannot request computer certificate.
    ... request a computer certificate for about 9 months. ... and verify that you can get a computer/server certificate from it. ... List of NetBt transports currently bound to the Redir ... DNS Host Name: srvr3.domain.com ...
    (microsoft.public.windows.server.security)
  • Re: Domain Controllers Cant reach Default Gateway...
    ... DNS it was missing the CNAME entry with the GUID for the other ... If a BIND server is being used, the design would be based on what ... One of them has Certificate ... Because the XP laptop wouldn't get the root certificate on it's own I ...
    (microsoft.public.win2000.active_directory)
  • Re: Cannot request computer certificate.
    ... I cannot get any type of certificate from the MMC. ... > As far as certutil - ping. ... >> Kerberos, or dns. ... >> List of NetBt transports currently bound to the Redir ...
    (microsoft.public.windows.server.security)