Re: PKI in multi sites/domains environment



Thanks !

As regards the isolation process (Americas users use only Americas
CA), ok for the first way, via persmissions. But I'm wondering
something, it prevents users from getting certificates from a
delocalized CA but it doesn't prevent users contacting the bad CA
(does it?). For exemple, when a user need a certificate for encrypting
his files. An automatic process will ask to a CA for a EFS
certificates. And if the process use the bad CA, it rolls back to an
other CA ? (Am I clear ?) or the process will use only CA where
permissions are ok (how can it check this without contacting the CA ?
permission are published in AD ? configuration context ?)

That's a great link (microsoft.com/pki) ! Thanks for this.

And what about X500 name constraints ? This function can be achieved
by constraint extensions ? For exemple I configure a CA with
constraint : issuing certificated only if subject CN match with
"*,DC=AMERICAS,DC=LOCAL". Will this serve ?

For the point 3, you want to say that CA certificates are published in
AD ? Is there a AD store like there is a User store in a computer ?
How does it work ?

I can't get what the purpose of the Issuance Policies (Low, Medium,
High). What is the interest ?

Thanks.

Regards,

--
P.J.A.
.



Relevant Pages

  • Re: PKI in multi sites/domains environment
    ... it prevents users from getting certificates from a ... but could lead to a lot of configuration headaches. ... Is there a AD store like there is a User store in a computer? ... this is a rudimentary implementation and most companies do custom assurance levels. ...
    (microsoft.public.windows.server.security)
  • Re: Certificate Types
    ... Certificates in the user store are ... Certificates in the machine store are only ... "Greg" wrote in message ...
    (microsoft.public.platformsdk.security)
  • Re: Silent certificate installation
    ... When I click to install the certificate I ... any bad guy can install certificates into the ... user store and add certificates to the root store ... I have a script included with my PKI book ...
    (microsoft.public.security)