Sign in
Windows PKI blog
Options
Email Blog Author
RSS for Posts
Atom
RSS for Comments
OK
Search Blogs
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Search
Tags
certificate requests
certificates
Certification authority
certutil
chain building
chain selection
Configuration
CRL
cross certification
key management
OCSP
powershell
qualified subordination
revocation
S/MIME
setup
troubleshooting
usability
Vista
webcast
whitepaper
Archive
Archives
June 2010
(2)
May 2010
(2)
April 2010
(3)
March 2010
(2)
February 2010
(1)
January 2010
(2)
December 2009
(2)
November 2009
(2)
October 2009
(2)
September 2009
(7)
August 2009
(10)
July 2009
(1)
June 2009
(2)
May 2009
(2)
April 2009
(2)
February 2009
(1)
January 2009
(4)
December 2008
(2)
October 2008
(3)
September 2008
(1)
July 2008
(1)
June 2008
(1)
May 2008
(1)
April 2008
(1)
February 2008
(2)
January 2008
(1)
November 2007
(1)
October 2007
(1)
September 2007
(1)
August 2007
(2)
July 2007
(2)
May 2007
(2)
April 2007
(1)
February 2007
(4)
January 2007
(1)
December 2006
(3)
November 2006
(1)
TechNet Blogs
>
Windows PKI blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows PKI blog
Firewall Rules for Active Directory Certificate Services
Posted
Fri, Jun 25 2010
by
oshekel
0
Comments
Below is a list of ports that need to be opened on Active Directory Certificate Services servers to enable HTTP and DCOM based enrollment The information was developed by Microsoft Consultant Services during one of our customer engagements Protocol Port...
Windows PKI blog
Design Considerations before Building a Two Tier PKI Infrastructure
Posted
Sat, Jun 19 2010
by
amerk-PFE
2
Comments
Environmental Dependencies: 1- Determine if the Active Directory Forest has Windows 2000 Domain Controllers. This is important because of modifications to the CertPublishers group scope, and permissions related to the AdminSDHolder role. These permissions...
Windows PKI blog
Certificate Path Validation in Bridge CA and Cross-Certification Environments
Posted
Wed, May 12 2010
by
siadukia
2
Comments
Recently, we’ve had a deluge of questions regarding chain building and selection, especially in the presence of cross-certified certificates. Hopefully, this post will make Crypto API 2 (CAPI2) chaining logic clearer and help enterprise admins design and troubleshoot their public key infrastructure....
Windows PKI blog
Powershell CRL Copy
Posted
Wed, May 12 2010
by
MS2065
0
Comments
This script writes a Certification Authority's Certificate Revocation List to HTTP based CRL Distribution Points via a UNC path. It checks to make sure that the copy was successful and that the CDPs have not and are not about to expire. Alerts/status...
Windows PKI blog
How to Request a Certificate With a Custom Subject Alternative Name
Posted
Thu, Apr 22 2010
by
alrad
0
Comments
Today many servers require some sort of SSL certificate to be deployed and in many cases custom names are involved. My colleague just published a document How to Request a Certificate With a Custom Subject Alternative Name that I strongly recommend reading...
Windows PKI blog
Disaster Recovery Procedures for Active Directory Certificate Services (ADCS)
Posted
Tue, Apr 20 2010
by
amerk-PFE
8
Comments
Introduction: When designing a public key infrastructure (PKI) for your organization, you must develop an effective disaster recovery plan to ensure that, in the event of failure of the computer hosting Certificate Services, you can recover in a timely...
Windows PKI blog
Enabling CEP and CES to enroll non-domain joined computers for certificates
Posted
Wed, Apr 7 2010
by
MS2065
0
Comments
This is just a cross post notification. Our friends from the Active Directory Services Team published an interesting read about Enabling CEP and CES to enroll non-domain joined computers for certificates .
Windows PKI blog
Windows Server 2008 R2 AD CS Migration Guide
Posted
Fri, Mar 19 2010
by
ltalbot
0
Comments
The official version of the new 2008 R2 ADCS Migration Guide is now available at http://technet.microsoft.com/en-us/library/ee126170(WS.10).aspx . The guide describes the necessary steps for a successful migration of both enterprise and standalone CAs...
Windows PKI blog
What CA types are supported for clustering?
Posted
Mon, Mar 8 2010
by
MS2065
2
Comments
There are two types of certification authorities: Standalone and Enterprise. Only Enterprise certification authorities have been tested for clustered installations. A very short but may be important statement.
Windows PKI blog
Whitepaper “HSPD-12 Logical Access Authentication and Active Directory Domains”
Posted
Wed, Feb 10 2010
by
MS2065
0
Comments
This document explains the interdependencies between Active Directory Domain Services (AD DS) and Public Key Infrastructure (PKI) related to Homeland Security Presidential Directive 12 (HSPD-12) smart card logon. Topics concerning the Federal PKI Common...
Windows PKI blog
Windows CA Performance Numbers
Posted
Mon, Jan 11 2010
by
oshekel
0
Comments
Below are some numbers we have measured when testing the Windows CA in our lab environment. Note that the numbers will change and depends on many factors (network topology, request types, other server workloads, etc.) However, the numbers are a good starting...
Windows PKI blog
Clustered Certification Authority maintenance tasks
Posted
Sun, Jan 10 2010
by
MS2065
0
Comments
The colleagues from the AskDS blog posted a quite valuable article about Clustered CA maintenance tasks .
Windows PKI blog
Server 2008 R2 ADCS Migration Guide Beta
Posted
Mon, Dec 21 2009
by
ltalbot
0
Comments
The beta version of the new 2008 R2 ADCS Migration Guide is now available at http://technet.microsoft.com/en-us/library/ee126140(WS.10).aspx . The guide describes the necessary steps for a successful migration of enterprise or standalone CAs from Windows...
Windows PKI blog
AD Schema Requirements for Windows PKI features
Posted
Fri, Dec 4 2009
by
alrad
0
Comments
There have been a number of questions about Active Directory (AD) schema requirements for the Windows PKI features so I decided this deserves a blog post. Cheat sheet 1. Version 2 and Version 3 certificate templates require Windows Server 2003 (version...
Windows PKI blog
How Certificates Are Created
Posted
Mon, Nov 9 2009
by
MS2065
0
Comments
The following text is a simple copy/paste from the TechNet article How Certificates Work (section How Certificates are Created ). Why am I posting this information to the blog? Quite simple: I recognize that it is often overlooked that the key pair generation...
Windows PKI blog
Certificate Revocation Checking Whitepaper
Posted
Sat, Nov 7 2009
by
Yogesh Mehta
0
Comments
A whitepaper on Certificate Revocation Checking in Windows Vista and Windows Server 2008 has been publshed on Technet here - http://technet.microsoft.com/en-us/library/ee619730(WS.10).aspx Topics in this whitepaper include: · What’s new in Windows Vista...
Windows PKI blog
Certificate Validation on Windows XP with Entrust SSP Issued HSPD-12 Certificates
Posted
Thu, Oct 22 2009
by
oshekel
0
Comments
On May 9 th , 2009 Entrust Managed Services (provider of HSPD-12 certificates) performed a key update ceremony on the Entrust Managed Services Root and SSP certification authorities. HSPD-12 certificates issued after May 9 th , 2009 will not work on the...
Windows PKI blog
BranchCache Deployment Guide for Windows Server 2008 R2 and Windows 7
Posted
Tue, Oct 6 2009
by
oshekel
1
Comments
A new deployment guide was published on Windows7 BranchCache. It covers the PKI requirements for this feature along with other deployment procedures. The full guide can be found here: BranchCache Deployment Guide for Windows Server 2008 R2 and Windows...
Windows PKI blog
Introducing Certificate Template API
Posted
Fri, Sep 25 2009
by
alrad
0
Comments
WARNING: USE OF THE SAMPLE CODE PROVIDED IN THIS ARTICLE IS AT YOUR OWN RISK. Microsoft provides this sample code "as is" without warranty of any kind, either express or implied, including but not limited to the implied warranties of merchantability and...
Windows PKI blog
Using VBScript to install CA on WS2008R2 server core
Posted
Fri, Sep 18 2009
by
shawncor
0
Comments
In my previous post I provided a script used for setup and installation of a CA using VBScript. The same script is capable of installing a CA on server core, where there is no UI available for installing. With the script and a few possible additional...
Windows PKI blog
Automated CA installs using VB script on Windows Server 2008 and 2008R2 [UPDATED]
Posted
Fri, Sep 18 2009
by
shawncor
2
Comments
Starting with Windows Server 2008 the CA product team introduced a set of COM objects that can be used to control the installation of CAs. Using VBScript you can quickly automate the setup and installation of a CA.Below is a script that is being used...
Windows PKI blog
Official Microsoft Team Blogs / Microsoft Blogs
Posted
Tue, Sep 15 2009
by
MS2065
0
Comments
If you are interested in reading more official Microsoft Team blogs, see http://blogs.technet.com/blogms/pages/directory-of-microsoft-team-blogs.aspx . This page is a great collection of valuable blog information.
Windows PKI blog
Certificate Enrollment Web Services Whitepaper
Posted
Mon, Sep 14 2009
by
JField
0
Comments
The Windows Server 2008 R2 Certificate Enrollment Web Services Whitepaper has been posted to the download center: you can download it here . This is just the initial document release for RTM. We plan to publish the content to various Technet locations...
Windows PKI blog
How to get request statistics by template in PowerShell
Posted
Wed, Sep 9 2009
by
alrad
0
Comments
I’ve been working with our support folks helping one of our customers. One of the things we wanted to learn about the environment is how many requests have been made for each certificate template that they issue. We have come up with this PowerShell script...
Windows PKI blog
Active Directory Certificate Services Features by SKU
Posted
Wed, Sep 2 2009
by
JField
0
Comments
We’ve had many requests for what services and features are available in what Windows Server version and SKU. The table below is our attempt to answer those questions. SKU Table (NOTE: entire table describes what is available in an Enterprise...
Page 1 of 4 (79 items)
1
2
3
4