all groups > iis security > april 2005 >
You're in the

iis security

group:

Issiung certifcates by a Windows 2000 Enterprise CA


Issiung certifcates by a Windows 2000 Enterprise CA Patrick
4/26/2005 12:28:01 AM
iis security: Hi All,

We have a AD domain with a Win2K and a Win2K3 server. IIS runs on ythe
Win2K3 server. I am about to install a Certificate Server on the Wn2K box
(anr using "Windows" Certifcatesand then use it to service https requests.

Has anyone of you come across/foresee problems with this setup?

TIA

Re: Issiung certifcates by a Windows 2000 Enterprise CA Jason Brown [MSFT]
4/28/2005 12:00:00 AM
Depends what you're going to use them for. If you're using them internally,
you can set your CA as a trusted root in your browsers, but if you want to
use them on the net, you can't guarantee the issuer will be trusted by your
clients. They'll get a warning box about that, but the SSL transactions will
still work as long as they hit OK to trust...


--
Jason Brown
Microsoft GTSC, IIS

This posting is provided "AS IS" with no warranties, and confers no rights.


[quoted text, click to view]
| Hi All,
|
| We have a AD domain with a Win2K and a Win2K3 server. IIS runs on ythe
| Win2K3 server. I am about to install a Certificate Server on the Wn2K box
| (anr using "Windows" Certifcatesand then use it to service https requests.
|
| Has anyone of you come across/foresee problems with this setup?
|
| TIA
|
| Patrick

Re: Issiung certifcates by a Windows 2000 Enterprise CA Patrick
4/29/2005 4:17:14 AM
Hi Jason,

Thanks for the post.
Yes, it will be used by the domain users only.

Will be there be any issues when it comes to upgrading the Windows 2000
server to Windows 2003? Most likely I will have to re-intslall the
Certificate Server, wouldn't I?

Also, in the event I need de-install Certificate Server from the Win2K box,
can I do that without disturbing the Active Directory?

Thanks heaps

Patrick

[quoted text, click to view]
AddThis Social Bookmark Button