Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


May 07, 2001

PKI and Your Win2K Network


RSS
Subscribe to Windows IT Pro | See More Windows 2000 Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Over the past several weeks, I’ve discussed Windows 2000's Certificate Services and how you can use the feature to build a public key infrastructure (PKI). I've also described how to configure a Web server to use Secure Sockets Layer (SSL) and how to use certificates to perform client authentication. If you’ve been following this series, you know that implementing PKI requires a lot of planning and work. Much of the work involves configuring server and client applications, as I demonstrated in my discussion about enabling SSL on Microsoft IIS 5.0 and Internet Explorer (IE) 5.0. To wrap up this series, I'll highlight a few Win2K services and applications that PKI can benefit.

Using PKI to Secure Email
Companies often transmit some of their most sensitive information via email, a practice that can be especially risky if you use a Web-based email client. Fortunately, you can protect such email at two levels: at the Outlook Web Access (OWA) server and at the client Web browser. To protect your OWA server, use the Microsoft Management Console (MMC) Internet Services Manager (ISM) snap-in to enable SSL on the Exchange virtual directory, as I described in my April 16 column. If you configure the Web server to require a secure channel when it accesses the Exchange directory, you make it very difficult for anyone to sniff and read email messages when users check mail remotely because the Web server’s public key encrypts all traffic. To protect email at the client level, use the Exchange 2000 Key Management Server (KMS) to issue certificates to users so that they can encrypt and sign messages themselves. KMS uses Win2K’s Certificate Services to produce digital certificates. Within Outlook, users specify whether they will encrypt email, which protects the contents, or sign it, which authenticates your indentify

EFS and Certificate Services
Although Encrypting File System (EFS) can function without Certificate Services, having a PKI can improve EFS manageability and recoverability. Whenever a user encrypts a file, the system saves the key with the file in two ways—once with the user’s key and a second time with the designated recovery agent’s key (by default, the built-in Administrator account is the designated recovery agent). This encryption scheme ensures that you can recover a file even if a user leaves the company. If you install an enterprise, you can issue file recovery certificates to additional user accounts. You can then use Group Policy to specify these users as recovery agents for individual Organizational Units (OUs) or for the entire domain, depending on the Group Policy Object (GPO) you’re editing.

Smart Cards and Certificate Services
You can also use Certificate Services to support smart-card technology, which Microsoft built into Win2K. Smart cards store the certificate and key that your system presents to Active Directory (AD) so that you don't have to enter the usual username and password. When you log on, AD prompts you for a PIN, much like the ATM at your bank does. You need an enterprise Certificate Authority (CA) to issue smart-card certificates. By default, users don’t have access to the smart-card certificate template, which means that they can't simply request their own certificates and sign up for smart-card authentication. Enrollment for a smart-card certificate should be a controlled procedure, similar to the process many companies use to issue employee identification badges. To help you establish this controlled procedure, enterprise CAs support an "enroll-on-behalf-of" feature that lets you request a certificate for a new user and map the certificate automatically.

Certificates and IPSec
Win2K's IP Security (IPSec) is an excellent method for encrypting any network traffic, regardless of the client or server application you use. When establishing an IPSec network session, the machines involved in the transaction authenticate using Kerberos, certificates, or a shared secret (i.e., a password). Kerberos authentication is an option only if both machines are members of the same AD forest, and shared-secret authentication isn't scalable or secure. As long as both machines have a common root CA in their IPSec policy configuration, you can use certificate authentication to provide a secure solution—even for communication that occurs among AD forests.

As you can see, PKI has many uses on a Win2K network. If you'd like me to cover any of these uses in more detail, post a comment in response to this article or email me.

End of Article



Reader Comments
Interesting.
We are setting up OWA and would like to require client Certificates. However, We would like to do this without having the CA directly on the internet. Is there a way to send out the certs without having them register. eg I would like to create the client certs and mail them to the users .

Glenn October 16, 2001


hello sir,

The informations at ur pages r very useful to have a good overview of all the topics.....i want to have an indepth knowledge of Pki n securing network resources......can u send me some links regarding the above mentioned topics....

thanx,


chetanjain April 18, 2002


SSL will provide a secure channel for the OWA but what if we want to encrypt or digitally sign the mails sent via OWA.

Eddie October 14, 2003


please send me computer microsoft certificate

Nizamulhaq May 04, 2004


Jason M. Laurvick used techniques to prevent unauthorized access from a network using VPN (Virtual private Networking) Server / Router configuration. Laurvick couldn't believe it was possible because server hardware is expensive, but through Altoria Solutions: http://www.altoria.com
Laurvick was able to install the necessary security to encrypt text data.

Anonymous User February 19, 2005 (Article Rating: )


I havs a problem.
We want to use certs to authenticate the computers before network access is granted. If a device fails authentication, they are given internet access only on a special VLAN and at a limited bandwidth.
The Enterasys switches are configured for 802.1x authentication and we tested using PEAP before we proceeded with this CA solution and everything worked fine so we know the switches are functioning fine.

We are a child domain of the parent and are installing CA. The root CA has been setup after which we installed the sub CA in our domain. This went fairly smooth. The ISA and Radius services are functioning fine with no errors in the event logs. The sub CA was used to generate the cert for our workstations and we have turned on auto enroll to test. Our test computer received the cert but it does not show in on the sub CA MMC under "Issued Certs". Some other systems like our DC's do.

When we connect the tes pc to the network, if fails vaildation with the following error: "Windows could not find a certificate to log you onto the network".

We have gone through it all and can not find the cause of this problem.


Anonymous User July 21, 2005 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Exchange Server and Outlook Whitepapers Email Controls and Regulatory Compliance

Take Control of Your Email: Understand the Business Reasons for Email Storage Management

Related Events Deep Dive into Windows Server 2008 R2 presented by John Savill

Bail Out Your Exchange Environment

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement