Local Certificate Authority Server

Local Certificate Authority Server

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Local Certificate Authority Server Rick 07-07-2006
Posted by =?Utf-8?B?Umljaw==?= on July 7, 2006, 1:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello I have configured an enterprise Certificate Authority Server that will
issue each email user a USER Certificate for Digital Signature purposes. On
our internal email with digitally signed mail we can read the email but when
I mail a free mail servers like yahoo or gmail the message is place on a
smime.p7m file. How can our local CA server be trusted?

Posted by Paul Adare on July 7, 2006, 4:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
microsoft.public.security news group, =?Utf-8?B?Umljaw==?=

> Hello I have configured an enterprise Certificate Authority Server that will
> issue each email user a USER Certificate for Digital Signature purposes. On
> our internal email with digitally signed mail we can read the email but when
> I mail a free mail servers like yahoo or gmail the message is place on a
> smime.p7m file. How can our local CA server be trusted?
>

Getting your CA publicly trusted is a difficult and time consuming process
and should only really be undertaken by those who wish to provide PKI
services as a part of their core business. The short answer to your question
is that your local CA can't be trusted outside of your organization, nor
should it be. If you want to exchange signed or encrypted email with people
outside of your organization you either need to purchase S/MIME certificates
from someone like Verisign or you need to have an internal issuing CA
subordinated to an external publicly trusted root.
The fact that your signatures appear as an smime attachment when sending to
Yahoo or Gmail has nothing at all to do with the fact that your CA isn't
externally trusted.

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie. How
lucky Adam was. He knew when he said a good thing, nobody had said it
before. Adam was not alone in the Garden of Eden, however, and does not
deserve all the credit; much is due to Eve, the first woman, and Satan, the
first consultant." - Mark Twain

Similar ThreadsPosted
remove certificate authority server September 4, 2007, 4:30 pm
How can I create a second certificate authority server for redunda September 20, 2006, 12:07 pm
Windows 2000 Certificate Authority (CA) Server - Can I delete Revo April 17, 2006, 9:03 pm
what type of certificate authority? June 16, 2005, 4:08 pm
Certificate Authority type June 16, 2005, 6:01 pm
Problem with certificate authority January 27, 2006, 9:03 am
Certificate Authority (CA) - Failover Possible? February 24, 2006, 8:20 pm
Microsoft Certificate Authority June 14, 2006, 8:25 am
Problem in Certificate Authority February 23, 2007, 4:09 am
Certificate Authority Settings May 22, 2007, 3:46 pm

The site map in XML format XML site map

Contact Us | Privacy Policy