Re: two CA certificates for IPSec or something...

From: Brian Komar [MVP] (bkomar_at_nospam.identit.ca)
Date: 09/17/05

  • Next message: Ondrej Sevecek: "Re: two CA certificates for IPSec or something..."
    Date: Sat, 17 Sep 2005 09:41:07 -0500
    
    

    Answers inline:
    In article <ezeM0$4uFHA.3556@TK2MSFTNGP12.phx.gbl>, "Ondrej Sevecek"
    <ondra at my_surname dot com> says...
    > is it possible to have more then one CA signing certificate on one
    > enterprise CA?
    No, the Microsoft CA will have a single, valid signing certificate for
    the issuance of new certificates. It is possible that after the renewal
    of a CA certificate, that two or more CA certificates will exist and me
    time valid, but only the active certificate is used to sign new
    requests. The previous certificates will be used to sign CRLs associated
    with that certificate.

    >
    > Or how to achieve this: to have two separate groups of computers using IPSec
    > where one group enrolls automatically, the other manually or with approval.
    > This should allow for restrictive and less restrictive IPSec filter rule
    > sets on a server.
    >

    You could use two certificate templates to accomplish this, but if you
    are applying different IPSec filters, the authentication can only
    indicate *which* root CA the chain is rooted.

    > O.
    >
    >
    >


  • Next message: Ondrej Sevecek: "Re: two CA certificates for IPSec or something..."

    Relevant Pages

    • Re: Certificate Trust List
      ... This posting is provided "AS IS" with no warranties, and confers no rights. ... I imported the CTL signing certificate in my ... >>Is the CTL signing certificate in your local profile? ...
      (microsoft.public.win2000.security)
    • Re: Certificate Revocation List (CRL) problem w/ Outlook XP
      ... the Signing Certificate using Outlook Clients. ... the Signing Certificate, the system fetches the Crl files to your Local ... If a Certificate found in the Certification Path has no CDP (Certificate ...
      (microsoft.public.security)
    • Re: Certificate Trust List
      ... I imported the CTL signing certificate in my ... the personal certificate store on my ... domain controller. ... >Is the CTL signing certificate in your local profile? ...
      (microsoft.public.win2000.security)
    • Re: Creating PKCS#7
      ... microsoft other then certificate store and another sample, ... >> that it doesnt contain the signing certificate I saw it in MSDN and it ... >> Muhammad Aftab Alam ...
      (microsoft.public.platformsdk.security)
    • Re: About Digital Signature
      ... I hope you bought the VBA/Office signing certificate. ... Your macros will not recognize any signing but Word 2000 will. ...
      (microsoft.public.word.vba.general)