windows server 2008 PKI


hi all

im implementing windows server 2008 pki using ad certificate service want implement 2 tier pki 1 standalone  offline ca , enterprise subordinate ca

i have article

http://blogs.technet.com/b/askds/archive/2009/10/13/designing-and-implementing-a-pki-part-ii.aspx

it's 1 there things can't figure ou

how can use  capolicy.inf file , the post-installation script , myhttppkivroot , configure that

and if didn't use of above happen pki servers?

thanks


tarek khairy

i've seen post-installation script url pointed crl distribution point / ca certificate distribution point. should create virtual directory on web server going host these data (if ca server you could create virtual directory pointing c:\windows\system32\certsrv\certenroll directory).

as url should consider url should accessible (e.g. local network, internet or both). if possible suggest url accessible both local network , internet used crl checking.

 

 

kind regards

 

martin



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL