Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- From: Paul Adare <pkadare@xxxxxxxxx>
- Date: Wed, 26 Mar 2008 17:19:06 +0100
On Wed, 26 Mar 2008 13:58:22 +0100, Pascal wrote:
Yes I agree with you and perhaps you dont understand my question as I
dont have a fluent english.
I have understood too that if I install the Root CA cert, I will trust
every subordinate CA even if I dont have their certificates installed.
But my question is "why does Microsoft recommend to install the root CA
and not only the subordinate CA on client computers as if just the
subordinate CA is installed on them, then ONLY certificates delivered
by this subordinate will be trusted.
If you don't trust the root then you by definition don't trust any part of
the chain. Simply installing a subordinate CA certificate on a client
computer is not enough. It isn't the process of installing a subordinate CA
certificate that completes the chain of trust, it is the fact that you
trust the root.
However, if we install the root CA certificate on computer, EVERY
certicates by EVERY CA subordinate will be trusted
Do you understand my question ?
If you don't trust the root, you don't trust any part of the PKI.
--
Paul Adare
MVP - Virtual Machines
http://www.identit.ca
Software is to computers as yeast is to dough. -- Chuck Bradshaw
.
- References:
- Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- From: Pascal
- Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- From: Brian Komar \(MVP\)
- Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- From: Pascal
- Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- From: Brian Komar \(MVP\)
- Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- From: Pascal
- Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- Prev by Date: Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- Next by Date: Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- Previous by thread: Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- Next by thread: Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
- Index(es):
Relevant Pages
|