Hi,
A little confused about what you want to accomplish here. Are you talking
about the CA's web enrolment functionality?
You can "recreate" the virtual directories on any IIS box, but how exactly
is that IIS box going to provide the ability to submit cert requests if it
doesn't have Certificate Services installed? I know you mentioned "adding
pointers from the CA to the IIS server", but that doesn't really make a lot
of sense to me...
Chees
Ken
[quoted text, click to view] "Edward Ray" <ewray@newsgroup.nospam> wrote in message
news:O1xRVuDVGHA.1688@TK2MSFTNGP11.phx.gbl...
: The Brain Komar texts implies that the enterprise subordinate CA (i.e.
: issuing CA) needs to reside on the same machine as IIS. From a security
: perspective, this seems like a poor design. From a network standpoint, it
: means I have to support multiple IIS servers in my LAN.
:
: Neither is acceptable. I would like to utilize my existing IIS server
(not
: on issuing CA) to provide certificate enrollment. Adding the virtual
: directories seems to be pretty simple, then adding pointers from the CA to
: the IIS server.
:
: Is their anything I am missing? If someone has a good reference or web
link
: on how to set up using this scenario, much appreciated.
:
:
: Edward W. Ray
: CISSP,MCSE+Security,GCIA, GCIH
:
: