CA store

CA store

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
CA store Jim 07-06-2006
---> Re: CA store Arek Iskra [MVP...07-09-2006
Posted by Jim on July 6, 2006, 4:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Windows has a Certificate store Manager; Tools>Options|Content tab and click
[certificates]. There are [import and export] and [Advanced] buttons. How do
I get an CA digital ID out of there for use in email. Why is this a problem
for users when seeking digital ID for encryption algorithms of work data?



Posted by Paul Adare on July 7, 2006, 4:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Windows has a Certificate store Manager; Tools>Options|Content tab and click
> [certificates]. There are [import and export] and [Advanced] buttons. How do
> I get an CA digital ID out of there for use in email. Why is this a problem
> for users when seeking digital ID for encryption algorithms of work data?
>

I'm not really following what you're asking here, can you clarify? Just
because you may have some certificates that are visible through IE does not
mean that these certificates are suitable for secure email.

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie. How
lucky Adam was. He knew when he said a good thing, nobody had said it
before. Adam was not alone in the Garden of Eden, however, and does not
deserve all the credit; much is due to Eve, the first woman, and Satan, the
first consultant." - Mark Twain

Posted by Arek Iskra [MVP] on July 9, 2006, 12:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Windows has a Certificate store Manager; Tools>Options|Content tab and
> click
> [certificates]. There are [import and export] and [Advanced] buttons. How
> do
> I get an CA digital ID out of there for use in email. Why is this a
> problem
> for users when seeking digital ID for encryption algorithms of work data?
>
>

Jim, you will have to enroll for appropriate Digital ID certificate for each
user. If you go through VeriSign they will give you step by step
instructions. In general, the enrollment process will take care of email
client configuration (Outlook).

If you already have a Digital ID certificate and you can't seem to use it
for email, you probably need to assign a signing/encryption pair in email
client. Assuming you're using Outlook and you have valid (non-expired)
Digital ID, go to Tools -> Options -> Security tab in Outlook. Click on
Settings button (next to S/MIME... drop down list). Over there you need to
assign both signing and encryption certificates. Leave the hash algorithm
and encryption algorithm as it is (should be SHA1/3DES, respectively).

Or is that not the problem you're experiencing?

--
Arek Iskra
MVP for Windows Server - Software Distribution



Posted by Jim on July 10, 2006, 11:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you.
The "certification store manager" does what for users, i.e. bank and
brokerage and customer? Is this for server<=> client verification on ssl?
How do we use the [import and export] and [advanced] features? For example,
if I use the [export\import] it goes to the doc folder. If I send a Works
doc or spreadsheet or database, do I use this technique to assign a CA to a
private job/work doc to verify authors authenticity?
> > Windows has a Certificate store Manager; Tools>Options|Content tab and
> > click
> > [certificates]. There are [import and export] and [Advanced] buttons.
How
> > do
> > I get an CA digital ID out of there for use in email. Why is this a
> > problem
> > for users when seeking digital ID for encryption algorithms of work
data?
> >
> >
>
> Jim, you will have to enroll for appropriate Digital ID certificate for
each
> user. If you go through VeriSign they will give you step by step
> instructions. In general, the enrollment process will take care of email
> client configuration (Outlook).
>
> If you already have a Digital ID certificate and you can't seem to use it
> for email, you probably need to assign a signing/encryption pair in email
> client. Assuming you're using Outlook and you have valid (non-expired)
> Digital ID, go to Tools -> Options -> Security tab in Outlook. Click on
> Settings button (next to S/MIME... drop down list). Over there you need to
> assign both signing and encryption certificates. Leave the hash algorithm
> and encryption algorithm as it is (should be SHA1/3DES, respectively).
>
> Or is that not the problem you're experiencing?
>
> --
> Arek Iskra
> MVP for Windows Server - Software Distribution
>
>




Similar ThreadsPosted
Certificate store question February 4, 2008, 1:01 pm
Store private key in assembly May 6, 2008, 5:56 am
Is there a way to get certificate store path from CERT_CONTEXT March 6, 2006, 11:07 am
Access to local machine store June 2, 2008, 4:08 am
how to check .pfx certificates in personal store remotely April 5, 2006, 11:50 am
Error in Signtool - "Personal" certifcate store was not found August 4, 2006, 9:10 pm
How to make privatekey of a certificate entirely non exportable from personal store? April 6, 2007, 5:47 am
Which Registry Values store these Windows Firewall GPO settings...... August 19, 2007, 6:45 am
Using ISP webspace to store Encrypted sensitive data. Comments ?? November 6, 2007, 6:16 pm
Deleting Archived Certificates from Users' My store on Workstations July 8, 2008, 3:50 pm

The site map in XML format XML site map

Contact Us | Privacy Policy