2003 PKI Design Question

From: Eric O'Callaghan (eric_ocallaghan_at_hotmail.com)
Date: 02/24/05


Date: Thu, 24 Feb 2005 15:54:15 -0500

Hi All,

I want to deploy a Intermediate CA (standalone subordinate to a third party
Trusted Root CA) and an Enterprise Issuing CA (sub to the Inetrmediate CA)
to avail of the auto-enrollment feature.
I plan to distribute the following types of certificates:

Digital Signatures
Secure Messaging Certificates (S/MIME)
EFS Certificates
Certificates for authentication (via smart cards)
Code Signing certificates

My questions are:
Will digital signatures & certificates issued to my users by the internal
issuing CA be trusted by external parties?
Is there a better way to do this? Am I opening up a potential can of worms
security wise with a Trusted Root CA?
Is it possible to generate certificate that do not chain to the trusted root
such as EFS/Authenication certs (via Policy CA)?

Sorry for the 'dumb' questions but I'm pretty new to PKI and just want to be
sure where I should be headed.

Thanks for your help.



Relevant Pages

  • I want to become a Certified CA (thanks)
    ... >manual install of my certificate into their Trusted Root ... >be allowed to issue/sign certificates. ... >sign my certificates just to do SSL AND I also do not ... >If becoming a CA costs too much as well, ...
    (microsoft.public.inetserver.iis.security)
  • Re: 2003 PKI Design Question
    ... As long as your certs chain to a trusted root, ... Any third party trusted root will require very rigorous vetting processes ... > I plan to distribute the following types of certificates: ...
    (microsoft.public.windows.server.security)
  • Re: Still cannot install 831464 hot fix..
    ... Check the local computer certificate store to see if the Trusted Root ... Certificates have been deleted or corrupted. ...
    (microsoft.public.windows.server.sbs)
  • Re: Import SSL certificate into Trusted Root
    ... You may possibly be installing it under user account rather than computer. ... You should now have Certificates for Local Computer under your console ... Right click on Trusted Root Certfication Authorities, ... and that Trusted Root Cert Authorities is selected for Certificate Store ...
    (microsoft.public.exchange.admin)