Re: Certs in non-domain environment:



Correct, you would store each other's certs (and the certs that sign those certs) in each other's store. Another option, if you don't already have PKI in place, is to use free certs from cacert.org and have them as the CA.


Mark Burnett


"Kristin Griffin" <kristin.l.griffin@xxxxxxxxx> wrote in message news:%23LH%23FIrXIHA.1212@xxxxxxxxxxxxxxxxxxxxxxx
Hi there.

I have been learning about PKI and AD CS. And there is alot of material
about using active Directory to hand out certs.
But what if you were in a non-domain environment. How would 2 companies use
each other's certs? Let's say that company A and company B each had AD CS
running on standalone machines. Let's say they each were part of a
workgroup instead of a domain.

In order to use each other's certts, would they need to manually exchange
certs, put them each other's cert store, and also exchange the Root CA cert
and put that in the certificate store (in two places I think)?

Or am I thinking about this all wrong?

Thanks for your help.

Kristin



.



Relevant Pages

  • Re: How do you associate private key with import cert?
    ... IE certificates panel and Certs snapin use. ... panel is that the IE display is filtered (i.e. in MY store, ... and select to include the private key (only possible if the private key has ...
    (microsoft.public.dotnet.security)
  • Re: importing certificate into "my" store
    ... The usual place to install others certificates (not including root CA certs) is in the "Other" ... certificate store. ... an associated private key, and which are invalid for other reasons (however MMC Certs SnapIn ...
    (microsoft.public.platformsdk.security)
  • Re: Enterprise root CA not re-trusted after manually deleted
    ... the AEDirectoryCache is the authoritative local copy of the AD and the client is not interested in the contents of the cert store at all. ... CA certs in AD). ... deleted root certs can automatically return or need a manual repair. ... When I then deleted the certificate manually from a computer's Trusted ...
    (microsoft.public.windows.server.security)
  • Re: How to verify CA for a X.509 certificate
    ... The article DOES check if the public key is in the store, ... to use it to explicitly verify the signature on the cert. ... root CA certs;-) then you should be golden. ... > is not secure as the issuer name can be forged quite easily. ...
    (microsoft.public.dotnet.security)
  • Copying Certificates from the Trusted Root certs store to the Personal Store on XPsp3
    ... I have successfully distributed a couple of private certificates by GPO ... GPO puts the certs into the container Computer \ Trusted Root ... DOES ANYONE HAVE A COMPREHENSIVE LIST OF CERTIFICATE STORE NAMES? ...
    (microsoft.public.windowsxp.security_admin)