Re: CAn CRL and GPO



You may want to consider an Enterprise CA for an AD domain as it has several
advantages and you could still use your stand alone root CA with the
Enterprise CA being a subordinate CA to it if your security needs dictate
such. According to the article below if your CA is a domain member installed
by a domain administrator it should publish the CRL to AD. If that is not
the case see the second link below on how to do it using dsstore for Windows
2000 and the last link to use certutil.exe -dspublish for Windows
03. --- Steve

http://technet2.microsoft.com/WindowsServer/en/Library/799053d3-2be3-4728-beff-71c82f69dc381033.mspx
http://support.microsoft.com/?kbid=271386
http://technet2.microsoft.com/WindowsServer/en/Library/073732b5-80f0-4cf0-bc8e-d8e055ce26491033.mspx

"fabrice" <emouchet@xxxxxxxx> wrote in message
news:%23CEz1MFOGHA.3284@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I have just installed a stand-alone CA. For security, it is a stand alone
server. not integrated in my local domain.
Domain users use outlook (2000, XP, and 2003) as mailer software.
Is there a way to force Outlook to consult the CRL, published by ma
stand-alone CA.
Can I publish revocated certificates in my Active Directory or in share
directory ?
Can I use GPO ?

thanks for your help.
fabrice




.



Relevant Pages

  • Re: PKI Question
    ... Because an Enterprise CA is integrated with Active Directory which requires ... stand-alone root CA. ... An enterprise root requires access to the Active ... You should not install an enterprise root on an offline domain ...
    (microsoft.public.security)
  • Re: active directory security
    ... >When I make a security change in active directory for a built in group ... >i.e (administrators,domain admins, and enterprise admins)the change ...
    (comp.os.ms-windows.nt.admin.security)
  • autologon vista
    ... Enterprise or Ultimate in an Active Directory domain. ... Autologon account would be a local account on the system ... Is that solution can be managed through group policy for Vista Enterprise ...
    (microsoft.public.windows.group_policy)
  • Re: Certificate chain issue with Ent Sub Ca & stand alone Root CA
    ... AD to an Enterprise subordinate CA that's included in AD. ... I save my CA certificate Request on a floppy disk. ... Submit it to the stand alone Root Ca and issue it. ...
    (microsoft.public.windows.server.security)
  • Re: Issuing CA - Common Name?
    ... enterprise CA it publishes certain information to Active Directory. ... enterprise CAs had the same common name then there would be 2 machines trying ... Click to high-light Active Directory Sites and Services[FQDN of domain ... We want to add a 2nd enterprise issuing ...
    (microsoft.public.security)

Quantcast