Re: Certs in non-domain environment:



Correct, you would store each other's certs (and the certs that sign those certs) in each other's store. Another option, if you don't already have PKI in place, is to use free certs from cacert.org and have them as the CA.


Mark Burnett


"Kristin Griffin" <kristin.l.griffin@xxxxxxxxx> wrote in message news:%23LH%23FIrXIHA.1212@xxxxxxxxxxxxxxxxxxxxxxx
Hi there.

I have been learning about PKI and AD CS. And there is alot of material
about using active Directory to hand out certs.
But what if you were in a non-domain environment. How would 2 companies use
each other's certs? Let's say that company A and company B each had AD CS
running on standalone machines. Let's say they each were part of a
workgroup instead of a domain.

In order to use each other's certts, would they need to manually exchange
certs, put them each other's cert store, and also exchange the Root CA cert
and put that in the certificate store (in two places I think)?

Or am I thinking about this all wrong?

Thanks for your help.

Kristin



.



Relevant Pages

  • Re: How do you associate private key with import cert?
    ... IE certificates panel and Certs snapin use. ... panel is that the IE display is filtered (i.e. in MY store, ... and select to include the private key (only possible if the private key has ...
    (microsoft.public.dotnet.security)
  • Re: importing certificate into "my" store
    ... The usual place to install others certificates (not including root CA certs) is in the "Other" ... certificate store. ... an associated private key, and which are invalid for other reasons (however MMC Certs SnapIn ...
    (microsoft.public.platformsdk.security)
  • Re: How to verify CA for a X.509 certificate
    ... The article DOES check if the public key is in the store, ... to use it to explicitly verify the signature on the cert. ... root CA certs;-) then you should be golden. ... > is not secure as the issuer name can be forged quite easily. ...
    (microsoft.public.dotnet.security)
  • Re: ipsec lan: IKE: no private key found, ideas?
    ... Have you got the certificates in the right stores [sounds like you have ... For the certs you have, computer personal store and corresponding trusted ... certificates with new private keys having cleared out [save the existing ...
    (microsoft.public.win2000.security)
  • Re: IIS and cert dialog on client
    ... > OK, I am not sure, but it seems, that IIS takes certs from the store: ... > store trust list... ...
    (microsoft.public.platformsdk.security)