| Thread | Last Post | Replies |
|
| Web enrollment for Stand alone root CA | 31 Oct 2008 13:04 GMT | 2 |
i am trying to implement Web Enrollment Pages on a different machine then the Stand Alone RootCA I encounter. the machines are not part of any domain i am getting
|
| Remove computer certificate | 30 Oct 2008 13:20 GMT | - |
Hi, a customer of mine has for a couple of years ago deployed en Standard CA on Windows 2003. This CA were deleted/removed 6 month ago and replaced with a new Enterprise Root CA. Now they realized that the old CA has deployed computer certificates to all PC in the enterprise, and ...
|
| CLM Offline unblock | 29 Oct 2008 23:43 GMT | 2 |
We are setting up a pilot CLM 2007 FP1 environment. We have obtained a Microsoft Base CSP compliant Smart Card. We have successfully configured a Smart Card profile with the appropriate CA template. We have defined all of the CLM roles with the appropriate accounts/groups. We ...
|
| master key encryption | 29 Oct 2008 04:53 GMT | 1 |
I am new to this area so please bear with me. I have been asked to look at encryption on our laptops and data on our usb's used. Does anyone know of any suitable method of storing a master encryption key for unlocking encrypted files that users have set on their data. When we
|
| CDP AIA extension page check boxes | 28 Oct 2008 11:06 GMT | 2 |
In the "Microsoft Windows Server 2003 PKI and certificate Securty" book page 108 table 6-3 I have a misunderstanding. Value 2 description is fit value 8 label and vice versa Did I get it wrong?
|
| Certificate Enrollment and CSPs | 27 Oct 2008 18:05 GMT | 1 |
My understanding of certificate enrollment is that the generated certificate request would support *all* of the CSPs named in the certificate template (if the client generating the request supported them). I have since been advised by a Microsoft person that this is not ...
|
| Computer autoenrollment failing | 24 Oct 2008 18:12 GMT | 9 |
I started doing auto enrollment of computers in preparation for RDP/TLS. I've been widening the coverage in our root domain which has 8000 user accounts and probably 2000-3000 Windows computers, mostly XP. Failures to issue certificates started accumulating in one area of our
|
| Silent removal of a trusted root CA cert | 23 Oct 2008 14:03 GMT | 1 |
I have a large number of clients (~50,000) that require removal of a trusted root CA cert that we added via group policy some time ago. I have downloaded and installed the Capicom SDK 2.1.0.2 and tested using the cstore.vbs sample script that comes with it. The script works great ...
|
| CAPOLICY.INF URL updates? | 22 Oct 2008 08:48 GMT | 1 |
Once set, is it possible to make changes to the url that was set initially on the Root CA via the capolicy.inf? In this case an environment that was to be accessible externally is now internal only and the url needs to be updated. I have tried updating the
|
| CRL Validity Extension | 22 Oct 2008 07:40 GMT | 7 |
In a Windows smartcard logon scenario, according to this KB paper http://support.microsoft.com/kb/887578/en-us in order to extend the validity period of a CRL in case of publishing failure, it is necessary to edit the registry key
|
| Partitioned CRLs | 21 Oct 2008 16:10 GMT | 5 |
We have a CA that has thousands of revoked certificates which leads to CRLs os several MBytes. On the next nenewal of the CA, we are thinking of partitioning the CRLs at each X number of issued certificates. The issued certificates
|
| exhaustive key search scenarios | 21 Oct 2008 12:16 GMT | 1 |
just getting into cryptography from an academic perspective and I wondered if any of you had thoughts on the following scenarios Suppose that an attacker has got hold of a piece of ciphertext that has been
|
| Support for Non-CLM Requests Plug-in | 17 Oct 2008 20:26 GMT | 3 |
How important is configuring this plug-in? I have CLM configured and see that my auto-enrolled certificates are being published by the exit module into the CLM SQL database. I think that is all I really wanted for those certificates as far as CLM goes. What do I gain by
|
| Verifying PKI with certutil | 17 Oct 2008 10:14 GMT | 2 |
I have installed a 2-tier-PKI on Windows Server 2008. One standalone-Offline-root-CA and one Enterprise-Online-SUB-CA. It looks fine if I check with pkiview.msc but with certutil I have questions. 1. Can you send me examples of the syntax for certutil -verify -urlfetch? I
|
| Delta CRLs | 16 Oct 2008 23:40 GMT | 1 |
Hello, if I use delta CRLs and they expire, will this stop smart card logon working?
|