Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


April 02, 2001

Configuring Your Own CA


RSS
Subscribe to Windows IT Pro | See More Configuration Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week, I discussed the public key infrastructure (PKI) and its uses in a Windows 2000 environment. I mentioned that Win2K includes Certificate Services, which lets you create your own Certificate Authority (CA). The CA is responsible for issuing the digital certificates that form the backbone of the public key infrastructure (PKI). Creating your own CA hierarchy is appropriate when you have control of the resource you want to protect and you have the desire and the ability to manage which users get the necessary credentials to access those resources. Conversely, a commercial CA is your only viable option when you either don’t have control over the resources you want to protect or the ability to verify credentials of those seeking certificates.

Once you decide that you want to provide your own CA, you can use the Control Panel Add/Remove Programs applet to install Certificate Services. Choose Add/Remove Windows Components, then click Certificates Services to launch an installation wizard that walks you through the CA configuration process. Let's review some of the configuration options you'll face as you configure your CA.

Certificate Hierarchies
Certificate hierarchies establish your "path of trust" throughout an organization. As the most trusted CA within your organization, the root CA issues certificates to confirm the validity of other CAs, known as subordinate CAs. Subordinate CAs can issue certificates that serve various purposes (e.g., for smart cards, Web authentications). Because of its importance, the root CA typically issues certificates to subordinate CAs only—not to end users. You must vigilantly secure the root CA machine; otherwise, someone might compromise the root CA's certificate store or the root CA might issue certificates to unauthorized machines—both of which would undermine your entire enterprise's PKI infrastructure.

Standalone vs. Enterprise CAs
In addition to deciding whether to configure a root or a subordinate CA, you must also decide whether yours will be a standalone or an enterprise CA. Enterprise CAs require Active Directory (AD), which identifies entities requesting certificates and determines whether they have the appropriate permissions. You should use enterprise CAs if you plan to issue certificates to users and computers within your organization only. You should use standalone CAs, which don't require AD, to issue certificates to users and computers outside of your organization. Standalone CAs are useful if you want to issue certificates to vendors or partners that need secure access to your company resources.

Certificate Revocation List
In addition to issuing certificates, the CA is also responsible for maintaining and publishing the certificate revocation list (CRL). Each certificate includes an expiration date. However, using the CRL, you can invalidate certificates before they expire, which might be necessary if a certificate becomes compromised or if you want to revoke access from a certificate holder.

Next week, we'll discuss implementing PKI and working with Web services to provide client and server authentication and encryption.

End of Article



Reader Comments
Good article, this covers the basics of creating a CA. But I am in a test environment with limited servers. Is it absolutely necessary to create Subordinate CA's? Or can the root CA do all the verification?

marc paniccia January 15, 2002


Yea you can have only a root CA. having subordinates are mainly for organization and security purposes. Big companies may have a different sub CA for diff departments, or an external CA to keep the root CA protected. Best practice is to keep the root CA offline and have the sub CAs hand out certificates.

peddietech March 24, 2009 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Related Events WinConnections and Microsoft® Exchange Connections

Deep Dive into Windows Server 2008 R2 presented by John Savill

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement