Re: New to CAs



On Mar 8, 10:30 pm, "S. Pidgorny <MVP>" <slavi...@xxxxxxxxx> wrote:
No, the requirement for trusting your certificates is not being a part of
your AD but having your CA certificate on the certificate trust list. So
there's a trivial solution to the alleged problem - make sure there is an
externally accessible authority info acess point and CRL distribution point
for your CA.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

*http://sl.mvps.org*http://msmvps.com/blogs/sp*

<jgal...@xxxxxxxxxxxxxxx> wrote in message

news:216f8833-f272-4aca-a43d-1a6a097e2dc4@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx



Hi.  I am a little new to working with CAs and cant seem to find an
answer to my question.  We are looking to assign certificates to
everything from our own software and ActiveX controls to websites we
have on the outside.  It would seem that we would want an Enterprise
Root CA but if someone connecting wasnt part of our active directory
it sounds like they would have a problem accessing the websites.  Im
not really sure what I need to setup to do this.  Any help would be
great.  Thanks.- Hide quoted text -

- Show quoted text -

I guess my real question here is whether or not the person using the
certificate has to be part of the Active Directory or just the person
requesting it. Basically if we create an ActiveX control and decide
to build a certificate for it and give it to a client outside our
organization, can they use it or does it somehow need to access the CA
because it is an Enterprise Root CA? The original requester whould be
part of our Active Directory.

.



Relevant Pages

  • Re: SSLinstall problem
    ... You error message seems to indicate there may already be a Certificate ... Authority but the CA certificate is not published in Active Directory. ... you try to install a CA on a non domain computer make sure you are trying to ... domain computer double check that the domain computer is using ONLY Active ...
    (microsoft.public.windows.server.networking)
  • Re: SSLinstall problem
    ... You error message seems to indicate there may already be a Certificate ... Authority but the CA certificate is not published in Active Directory. ... you try to install a CA on a non domain computer make sure you are trying to ... domain computer double check that the domain computer is using ONLY Active ...
    (microsoft.public.windows.server.security)
  • Re: WLAN Server Certificate for private internal AD Domain
    ... > Does anyone know if that FQDN has to correspond to my Active Directory ... you can also use a Certificate issued by your own ... > on the internet therefore I am unable to prove to verisign that I am ...
    (microsoft.public.internet.radius)
  • [Concepts]: cn and userCertificate vs userPrincipalName
    ... Windows PKI and Active Directory quite well - you go to the Web portal, ... certificate to authenticate, ...
    (microsoft.public.windows.server.security)
  • Installing X509Certificate to the cert store programatically
    ... I'm having a bit of difficulty installing an X509Certificate which I have ... created from the Active Directory "userCertificate" property of a user in my ... Now once this has finished I go and check the certificate store and I can't ...
    (microsoft.public.dotnet.framework.webservices.enhancements)