shutting down a trusted CA and raising a new trusted CA

shutting down a trusted CA and raising a new trusted CA

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
shutting down a trusted CA and raising a new trusted CA =?Utf-8?B?Y29icmE=?= 07-14-2005
Posted by =?Utf-8?B?Y29icmE=?= on July 14, 2005, 1:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
hi all

currently we have a trusted CA running and issuing certificates, but since
it is not accessible most of the time, Certifcates for IIS Portal Users can
not be issued in time.

Therefor we need to make a new TRUSTED CA in our region.

There are approx 500 Users and 100 user migrations per year.

Since the Certificate that the CA issues must be trusted, what options do we
have?

Can we have a new CA, and make a trusted root certificate for the IIS Server
and make Certificates for all users and map the new ones to the already
existing users on the IIS (like many-to-one)

What needs to be done so the end user does not realize that there is a new
CA, and what is needed for a trusted certifacate (all green, no yellow in the
dialog box)

im sorry if my explanation is a bit rough, but im doing a solution design
and am not really a CA specialist. It would be helpfull to have some valuable
input form professionals on what is realistic and what is not.




Posted by =?Utf-8?B?V29uZyBUdWNrIFdhaA== on July 14, 2005, 10:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
In the real world, the root CA is always store offline for security reason.
So what they do is to create a CA Hierarchy, and let the lower level CA
(issuing CA) for certificate delpoyment. This will be transparent to users
regardless of whether the root CA is offline or not as it is now not the one
who issue cert directly.

Check out on this site for more detail deployment infor.

"http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/DepKit/27bdfc11-96fd-4082-8458-8111af7d6abd.mspx"

HTH.


"cobra" wrote:

> hi all
>
> currently we have a trusted CA running and issuing certificates, but since
> it is not accessible most of the time, Certifcates for IIS Portal Users can
> not be issued in time.
>
> Therefor we need to make a new TRUSTED CA in our region.
>
> There are approx 500 Users and 100 user migrations per year.
>
> Since the Certificate that the CA issues must be trusted, what options do we
> have?
>
> Can we have a new CA, and make a trusted root certificate for the IIS Server
> and make Certificates for all users and map the new ones to the already
> existing users on the IIS (like many-to-one)
>
> What needs to be done so the end user does not realize that there is a new
> CA, and what is needed for a trusted certifacate (all green, no yellow in the
> dialog box)
>
> im sorry if my explanation is a bit rough, but im doing a solution design
> and am not really a CA specialist. It would be helpfull to have some valuable
> input form professionals on what is realistic and what is not.
>
>
>

Similar ThreadsPosted
SSL not trusted August 27, 2007, 3:26 am
trusted ip address August 7, 2005, 10:23 am
Re: Can Microsoft be trusted? October 4, 2005, 3:06 am
Re: Can Microsoft be trusted? October 4, 2005, 7:15 am
Re: Can Microsoft be trusted? October 5, 2005, 12:02 pm
How to add certificates to the "Trusted Publishers" ? March 28, 2007, 5:19 pm
Updating Trusted Root CA May 6, 2008, 4:31 pm
Can we default to a trusted domain in IIS prompt? December 27, 2005, 1:11 pm
Trusting Certs from Non Trusted root March 23, 2007, 6:38 pm
Upon Logon, IE Trusted Sites trying to automatically be added -- help. July 25, 2005, 8:20 pm

The site map in XML format XML site map

Contact Us | Privacy Policy