CA Cryptographic service provider?


hello,

i planning install single tier enterprise ca on dedicated windows 2008 r2 server. we still have windows xp sp3 workstations and have questions "cryptography" options on certificate authority installation wizard.

the "select cryptographic service provider (csp)" -selection defaults "rsa#microsoft software key storage provider". i'am not sure can select it, or of "cryptography next generation (cng)" providers (marked #).

does have information csp i should select?

i believe windows 2003 ca defaults "microsoft strong cryptographic provider" thinking of selecting guarantee compatibility windows xp.

any recommendations on "key character lenght" , "hash algorithm signing certificates" welcome.

thanks

lakend


you should use strongest provider (which provides additional features) supported operating system runs ca service. in case microsoft key storage provider. not use legacy provider (strong or enhanced csp). microsoft ksp have several options: xxx#microsoft key storage provider, xxx -- public key algorithm supported provider. here must select algorithm supported certificates clients. rsa internet pki standard algorithm supported certificate clients.

in other words, "safe" configuration rsa#microsoft key storage provider, signature algorithm = "sha1" , key length 2048. following variations possible without affecting many clients: change key length 4096 (i don't see big deal here) and change to sha256 signature algorithm. however, legacy clients (windows xp , windows server 2003) may not work algorithm (they require updates to support sha2 algorithms).


my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
check out new: powershell fciv tool.



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL