Subscribe to Windows IT Pro
April 19, 2004 12:00 AM

Uncover PKI and Certificate Services in Windows Server 2003

Working with enterprise and standalone CAs
Windows IT Pro
InstantDoc ID #42172
Rating: (0)

Publishing Certificates and CRLs
An enterprise CA uses AD to store and publish certificates, complete CRLs, and delta CRLs. Both a standalone CA and an enterprise CA can also publish to the file system. Each certificate published in AD automatically maps to the Windows account of its requestor. AD adds the certificate to the multivalued userCertificate attribute of a user or inetOrgPerson AD object. However, not every certificate that an enterprise CA generates is automatically published in AD. Examples of certificates that aren't automatically published are an enrollment agent or certificate trust list (CTL) signing certificate.

A standalone CA can publish issued certificates to AD, but this step isn't the default behavior. A standalone CA will automatically publish certificates to AD only if an enterprise administrator installs the CA on a member server joined to the domain. You can obviously always publish the certificates manually to AD.

The Best CA for the Job
Now that you're aware of the differences between an enterprise CA and a standalone CA, you can pick the best option for your situation. A Windows 2003 enterprise CA typically is best suited for enterprise certificate users who have an AD user account and who use Kerberos to authenticate to the AD infrastructure. A Windows 2003 standalone CA typically is best suited for external users (e.g., extranet users) who don't have an internal Windows account.

Resources
You can obtain the following articles from Security Administrator's Web site at http://www.winnetmag.com/windowssecurity.

Jan De Clercq
"Understanding Windows PKI Certificate Revocation," March 2004, InstantDoc ID 41572
"Windows Server 2003 PKI Key Archival and Recovery," February 2004, InstantDoc ID 41281
"Windows Server 2003 PKI Certificate Autoenrollment," January 2004, InstantDoc ID 40948



Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.