Question on Enterprise Subordinate CA configuration

Question on Enterprise Subordinate CA configuration

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Question on Enterprise Subordinate CA configuration Marlon Brown 04-02-2007
Posted by Marlon Brown on April 2, 2007, 12:21 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,
I configured a Win2003 server to be my offline root ca (workgroup).

Now I am configuring an "Enterprise Subordinate CA", Windows 2003
Enterprise.

On my Win2003 Enterprise Server "IssuingCA" server, I go to Control Panel,
Add/Remove Programs, I select "Certificate Services". Then I select
"Enterprise Subordinate CA".

My question is this:
"Use an existing key"= I am following the Help file instructions on how to
setup an Enterprise Subordinate CA. It says that here that I should "import"
the .pfx file.

Can you please clarify where I should import such .pfx file from? If it is
from the Offline Root CA, please tell me exactly location I should get this.
I am kind of confused on this.



Posted by Brian Komar [MVP] on April 2, 2007, 6:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
MarlonBrown@discussions.microsoft.com says...
> Hi,
> I configured a Win2003 server to be my offline root ca (workgroup).
>
> Now I am configuring an "Enterprise Subordinate CA", Windows 2003
> Enterprise.
>
> On my Win2003 Enterprise Server "IssuingCA" server, I go to Control Panel,
> Add/Remove Programs, I select "Certificate Services". Then I select
> "Enterprise Subordinate CA".
>
> My question is this:
> "Use an existing key"= I am following the Help file instructions on how to
> setup an Enterprise Subordinate CA. It says that here that I should "import"
> the .pfx file.
>
> Can you please clarify where I should import such .pfx file from? If it is
> from the Offline Root CA, please tell me exactly location I should get this.
> I am kind of confused on this.
>
>
>
The instructions sound a little off. I would recommend
using the Best Practices white paper available at
www.microsoft.com/pki instead of the Help files in this
case.

You would not be using an existing key, since you have
never built the CA before. You would generate the
request file (a .req file) and then submit that request
file at your offline CA.

The CA will issue a certificate which you should export
to a PKCS #7 file (.p7b). You would then import the .p7b
file at the subordinate enterprise CA to complete the
installation. This ties the certificate back to the key
pair you generated for the new CA.

Brian

Similar ThreadsPosted
Stand-alone vs Enterprise subordinate CA? March 9, 2007, 12:23 pm
PKI question, trusting subordinate CA January 1, 2006, 4:24 am
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
CAs: Enterprise root on parent domain, subordinate on child domain March 20, 2008, 10:28 am
question about removing enterprise CA February 6, 2007, 3:08 pm
General antispyware question for - enterprise deployment August 5, 2005, 5:31 pm
Upgrading to Windows 2003 Enterprise Edition Enterprise CA October 18, 2005, 4:59 am
root ca/subordinate ca October 3, 2007, 9:11 am
subordinate ent CAs don't publish certs to AD after Win 2k3 SP1 July 23, 2005, 1:00 pm
Change from Root CA to Subordinate CA February 2, 2006, 11:36 am

The site map in XML format XML site map

Contact Us | Privacy Policy