Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


May 07, 2001

PKI and Your Win2K Network


RSS
Subscribe to Windows IT Pro | See More Windows 2000 Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Over the past several weeks, I’ve discussed Windows 2000's Certificate Services and how you can use the feature to build a public key infrastructure (PKI). I've also described how to configure a Web server to use Secure Sockets Layer (SSL) and how to use certificates to perform client authentication. If you’ve been following this series, you know that implementing PKI requires a lot of planning and work. Much of the work involves configuring server and client applications, as I demonstrated in my discussion about enabling SSL on Microsoft IIS 5.0 and Internet Explorer (IE) 5.0. To wrap up this series, I'll highlight a few Win2K services and applications that PKI can benefit.

Using PKI to Secure Email
Companies often transmit some of their most sensitive information via email, a practice that can be especially risky if you use a Web-based email client. Fortunately, you can protect such email at two levels: at the Outlook Web Access (OWA) server and at the client Web browser. To protect your OWA server, use the Microsoft Management Console (MMC) Internet Services Manager (ISM) snap-in to enable SSL on the Exchange virtual directory, as I described in my April 16 column. If you configure the Web server to require a secure channel when it accesses the Exchange directory, you make it very difficult for anyone to sniff and read email messages when users check mail remotely because the Web server’s public key encrypts all traffic. To protect email at the client level, use the Exchange 2000 Key Management Server (KMS) to issue certificates to users so that they can encrypt and sign messages themselves. KMS uses Win2K’s Certificate Services to produce digital certificates. Within Outlook, users specify whether they will encrypt email, which protects the contents, or sign it, which authenticates your indentify

EFS and Certificate Services
Although Encrypting File System (EFS) can function without Certificate Services, having a PKI can improve EFS manageability and recoverability. Whenever a user encrypts a file, the system saves the key with the file in two ways—once with the user’s key and a second time with the designated recovery agent’s key (by default, the built-in Administrator account is the designated recovery agent). This encryption scheme ensures that you can recover a file even if a user leaves the company. If you install an enterprise, you can issue file recovery certificates to additional user accounts. You can then use Group Policy to specify these users as recovery agents for individual Organizational Units (OUs) or for the entire domain, depending on the Group Policy Object (GPO) you’re editing.

Smart Cards and Certificate Services
You can also use Certificate Services to support smart-card technology, which Microsoft built into Win2K. Smart cards store the certificate and key that your system presents to Active Directory (AD) so that you don't have to enter the usual username and password. When you log on, AD prompts you for a PIN, much like the ATM at your bank does. You need an enterprise Certificate Authority (CA) to issue smart-card certificates. By default, users don’t have access to the smart-card certificate template, which means that they can't simply request their own certificates and sign up for smart-card authentication. Enrollment for a smart-card certificate should be a controlled procedure, similar to the process many companies use to issue employee identification badges. To help you establish this controlled procedure, enterprise CAs support an "enroll-on-behalf-of" feature that lets you request a certificate for a new user and map the certificate automatically.

Certificates and IPSec
Win2K's IP Security (IPSec) is an excellent method for encrypting any network traffic, regardless of the client or server application you use. When establishing an IPSec network session, the machines involved in the transaction authenticate using Kerberos, certificates, or a shared secret (i.e., a password). Kerberos authentication is an option only if both machines are members of the same AD forest, and shared-secret authentication isn't scalable or secure. As long as both machines have a common root CA in their IPSec policy configuration, you can use certificate authentication to provide a secure solution—even for communication that occurs among AD forests.

As you can see, PKI has many uses on a Win2K network. If you'd like me to cover any of these uses in more detail, post a comment in response to this article or email me.

End of Article



Reader Comments
Interesting.
We are setting up OWA and would like to require client Certificates. However, We would like to do this without having the CA directly on the internet. Is there a way to send out the certs without having them register. eg I would like to create the client certs and mail them to the users .

Glenn October 16, 2001


hello sir,

The informations at ur pages r very useful to have a good overview of all the topics.....i want to have an indepth knowledge of Pki n securing network resources......can u send me some links regarding the above mentioned topics....

thanx,


chetanjain April 18, 2002


SSL will provide a secure channel for the OWA but what if we want to encrypt or digitally sign the mails sent via OWA.

Eddie October 14, 2003


please send me computer microsoft certificate

Nizamulhaq May 04, 2004


Jason M. Laurvick used techniques to prevent unauthorized access from a network using VPN (Virtual private Networking) Server / Router configuration. Laurvick couldn't believe it was possible because server hardware is expensive, but through Altoria Solutions: http://www.altoria.com
Laurvick was able to install the necessary security to encrypt text data.

Anonymous User February 19, 2005 (Article Rating: )


I havs a problem.
We want to use certs to authenticate the computers before network access is granted. If a device fails authentication, they are given internet access only on a special VLAN and at a limited bandwidth.
The Enterasys switches are configured for 802.1x authentication and we tested using PEAP before we proceeded with this CA solution and everything worked fine so we know the switches are functioning fine.

We are a child domain of the parent and are installing CA. The root CA has been setup after which we installed the sub CA in our domain. This went fairly smooth. The ISA and Radius services are functioning fine with no errors in the event logs. The sub CA was used to generate the cert for our workstations and we have turned on auto enroll to test. Our test computer received the cert but it does not show in on the sub CA MMC under "Issued Certs". Some other systems like our DC's do.

When we connect the tes pc to the network, if fails vaildation with the following error: "Windows could not find a certificate to log you onto the network".

We have gone through it all and can not find the cause of this problem.


Anonymous User July 21, 2005 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

The Desktop tab is missing from the Display Properties in Windows XP?

...

Microsoft's Olympic Gold

With world records being broken at a dizzying pace, the 2008 Summer Olympics in Beijing has drawn massive audiences from around the world, most watching the games via traditional TV coverage. But behind the scenes, a massive array of technology is ...


Exchange Server and Outlook Whitepapers Anonymizers – The Latest Threat to Your Web Security

Replay for Exchange: Enterprise Protection and an Affordable Price

ETX Driving Embedded I/O

Related Events Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.
Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Deploying SharePoint! In-Person Event Series – 8 Cities
Discover best practices and tips for deploying the perfect SharePoint infrastructure. Early Bird Price of $99 extended till Sept. 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16 in London.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing