Certs in non-domain environment:



Hi there.

I have been learning about PKI and AD CS. And there is alot of material
about using active Directory to hand out certs.
But what if you were in a non-domain environment. How would 2 companies use
each other's certs? Let's say that company A and company B each had AD CS
running on standalone machines. Let's say they each were part of a
workgroup instead of a domain.

In order to use each other's certts, would they need to manually exchange
certs, put them each other's cert store, and also exchange the Root CA cert
and put that in the certificate store (in two places I think)?

Or am I thinking about this all wrong?

Thanks for your help.

Kristin


.



Relevant Pages

  • Re: Problem with CAPICOM ... Import Certificates and Signin ...
    ... IE does some filtering for certs in MY cert store. ... > I can choose certificates that i want to import under IE. ...
    (microsoft.public.platformsdk.security)
  • using certs in non-domain environments:
    ... about using active Directory to hand out certs. ... In order to use each other's certts, would they need to manually exchange ... certs, put them each other's cert store, and also exchange the Root CA cert ...
    (microsoft.public.security)
  • Re: ca eventlog errors
    ... While the error messages may not be causing showstopper issues, ... When the error message states "...when processing requires Active Directory ... Check the CA cert and one of the issued certs to see if any of them have ... >> Since you installed it on a domain controller it would have made more ...
    (microsoft.public.windows.server.security)
  • Re: Active Directory Mapping with RFC822 Name vs. Principal Name?
    ... Yes, server is a Windows 2003 Server, with Active Directory. ... The Subject in the client certs look like (viewed using MS Cert ...
    (microsoft.public.platformsdk.security)
  • Enterprise vs Standalone CA
    ... Our CA will used to produce certs to be used for IPSec, website, and ... email encryption. ... Users will request certs ... like this information to be published in the Active Directory. ...
    (microsoft.public.win2000.security)