Sign In
Windows PKI blog
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
AD CS documentation updates
architecture
CA
certificate requests
certificates
Certification authority
certifiication authority
certreq request
certutil
chain building
chain selection
Configuration
cryptography
Homeland Security Presidential Directive 12
HSPD-12
key management
PKI
powershell
security update pki web services enrollment
setup
SHA2 NIST SP800-78-2 SP800-57
troubleshooting
usability
Vista
whitepaper
Archive
Archives
May 2012
(1)
April 2012
(2)
March 2012
(2)
February 2012
(1)
January 2012
(2)
December 2011
(1)
October 2011
(3)
September 2011
(2)
August 2011
(3)
June 2011
(2)
March 2011
(2)
February 2011
(3)
September 2010
(1)
August 2010
(3)
June 2010
(2)
May 2010
(2)
April 2010
(2)
March 2010
(2)
February 2010
(1)
January 2010
(2)
December 2009
(2)
November 2009
(2)
October 2009
(2)
September 2009
(7)
August 2009
(10)
July 2009
(1)
June 2009
(2)
May 2009
(2)
April 2009
(2)
February 2009
(1)
January 2009
(4)
December 2008
(2)
October 2008
(3)
September 2008
(1)
July 2008
(1)
June 2008
(1)
May 2008
(1)
April 2008
(1)
February 2008
(2)
January 2008
(1)
November 2007
(1)
October 2007
(1)
September 2007
(1)
August 2007
(2)
July 2007
(2)
May 2007
(2)
April 2007
(1)
February 2007
(4)
January 2007
(1)
December 2006
(3)
November 2006
(1)
TechNet Blogs
>
Windows PKI blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Windows PKI blog
Visual Basic for Applications and SHA2
Posted
25 days ago
by
Adam Stasiniewicz
0
Comments
I was recently helping a customer deploy a SHA-256 based PKI. As part of the retirement of their old PKI, we reissued the code signing certificates used by their developers. We found that the Visual Studio 2010 developers had no issue with the new code...
Windows PKI blog
Best Practice for Configuring Certificate Template Cryptography
Posted
1 month ago
by
Kurt L Hudson
0
Comments
Starting with Windows Vista and Windows Server 2008, the option to utilize Key Storage Providers (KSPs) in addition to Cryptographic Service Providers (CSPs) was added. These options are available when you create a Certificate Template and configure the...
Windows PKI blog
Network Device Enrollment Service (NDES) now on the TechNet Wiki
Posted
1 month ago
by
Kurt L Hudson
0
Comments
The Network Device Enrollment Service (NDES) whitepaper is now on the TechNet Wiki and I have already made a few updates that were requested. The old download center location has been updated to reflect that we've posted to the update to the TechNet Wiki...
Windows PKI blog
Offline CA articles posted to the TechNet Wiki
Posted
2 months ago
by
Kurt L Hudson
1
Comments
Amer Kamal recently posted two articles regarding the security and maintenance of offline CAs based on frequently asked questions from customers. These articles posted as: Security Best Practices for Offline CAs and Offline CA Maintenance Tasks...
Windows PKI blog
HSPD-12 Logical Access Authentication and 2008 Active Directory Domains on Download Center
Posted
2 months ago
by
Kurt L Hudson
2
Comments
A follow-up document to the original HSPD-12 Logical Access Authentication and Active DIrectory Domains document has just been posted to the download center. The follow-up document demonstrates the increased flexibility of FIPS 201 PIV-II compliant smart...
Windows PKI blog
Connecting iPads to an Enterprise Wireless 802.1x Network Using Certificates and Network Device Enrollment Services (NDES)
Posted
2 months ago
by
Amerk [MSFT]
1
Comments
Important notice : Microsoft does not support any apple products, if you need to troubleshoot any problem related to apple products, please refer to http://www.apple.com/support I am often asked by customers how to deploy certificates to iPads using...
Windows PKI blog
Decommissioning an Old Certification Authority without affecting Previously Issued Certificates and then Switching Operations to a New One
Posted
4 months ago
by
Amerk [MSFT]
2
Comments
Jonathan Stephens posted an excellent Blog about this topic ; however, it didn’t include the steps. As a result, I decided to type this Blog detailing the steps required. The following assumptions have to be met before proceeding with these steps...
Windows PKI blog
EFS Certificates may be recovered as CNG certificates when CAPI CSP is required
Posted
4 months ago
by
Kurt L Hudson
0
Comments
If a Key Recovery Agent (KRA) certificate is stored in a Cryptography Next Generation (CNG) Key Service Provider (KSP), the certutil -RecoverKey command will by default recover a key as a CNG certificate. This default behavior could cause an issue if...
Windows PKI blog
Windows PowerShell script for Setting up a CA on Windows Server 2008 and Windows Server 2008 R2
Posted
5 months ago
by
Kurt L Hudson
0
Comments
Microsoft MVP, Vadims Podans , has written and posted a Windows PowerShell script that can be used to setup a certification authority (CA). He posted his Windows PowerShell Script on the TechNet Script Repository as Setup Certification Authority with...
Windows PKI blog
Key Recovery vs Data Recovery Differences
Posted
7 months ago
by
Amerk [MSFT]
0
Comments
I am often asked when talking to my customers about the differences between Key Recovery and Data Recovery for encrypted files, in addition to which method to use. As a result, This Blog will focus on both areas, explaining the differences and best practices...
Windows PKI blog
How to decommission a Windows enterprise certification authority and how to remove all related objects
Posted
7 months ago
by
Kurt L Hudson
1
Comments
The Windows KB article 889250 titled "How to decommission a Windows enterprise certification authority and how to remove all related objects from Windows Server 2003 and from Windows Server 2000" has been revised on the TechNet Wiki to include information...
Windows PKI blog
Does Enterprise PKI (PKIVIEW) support OCSP?
Posted
7 months ago
by
Kurt L Hudson
0
Comments
A common question from certification authority administrators is "Does Enterprise PKI (PKIView) support OCSP?" Yes, the Microsoft Management Console (MMC) Enterprise PKI ( PKIView ), supports the When setting up Certificate Extensions, you must ensure...
Windows PKI blog
Updated requirements for a Windows Server 2008 R2 domain controller certificate from a 3rd party CA
Posted
7 months ago
by
Kurt L Hudson
2
Comments
Ingolfur has written a blog post as well as a TechNet Wiki article describing how a Windows Server 2008 R2 certification authority (CA) parses certificates, especially those from a third-party (3rd party) non-Microsoft CA. He also covers the Key Distribution...
Windows PKI blog
Windows 8 Developer Preview and AD CS / PKI: Cannot Get a Certificate from Web
Posted
8 months ago
by
Kurt L Hudson
3
Comments
If you are using Windows Developer Preview and have difficulty obtaining or downloading a certificate using Internet Explorer 10 (IE 10), try using compatibility mode. Turning on Compatibility View is the same in IE10 as in IE9, so you can follow the...
Windows PKI blog
Internet Explorer 9 and Certificate Enrollment using Certificate Authority Web Enrollment
Posted
9 months ago
by
Kurt L Hudson
1
Comments
If you run into an issue where you are unable to download or save certificates using Internet Explorer 9 (IE 9) and the Certificate Authority Web Enrollment service of a certification authority, you should be sure to disable the enhanced security option...
Windows PKI blog
Active Directory Certificate Services Frequently Asked Questions - needs your help!
Posted
9 months ago
by
Kurt L Hudson
4
Comments
If you have commonly asked questions about certificate services or PKI that you think should be listed in the Active Directory Certificate Services Frequently Asked Questions (AD CS FAQ ) list, I encourage you to submit them to the TechNet Wiki posting...
Windows PKI blog
AD CS Content Updates
Posted
9 months ago
by
Kurt L Hudson
0
Comments
The following documentation updates have been recently made: AD CS: Deploying Cross-forest Certificate Enrollment - updated with a link to the download center version of the document Additional documents added to the "future" consolidated download...
Windows PKI blog
Important Security Update for Windows Server: Active Directory Certificate Services Web Enrollment!
Posted
11 months ago
by
Kurt L Hudson
1
Comments
An important security update, described in MS11-051 ( http://go.microsoft.com/fwlink/?LinkId=217101 ) was released today. The update fixes a cross-site scripting vulnerability in the sample web enrollment ASP pages that are part of Active Directory Certificate...
Windows PKI blog
Implementing LDAPS (LDAP over SSL)
Posted
11 months ago
by
Kurt L Hudson
2
Comments
LDAP over SSL (LDAPS) is becoming an increasingly hot topic - perhaps it is because Event Viewer ID 1220 is catching people's attention in the Directory Service Log or just that people are wanting the client to server LDAP communication encrypted. The...
Windows PKI blog
Deployment of the new Federal Common Policy CA Root Certificate
Posted
over 1 year ago
by
MS2065 [MSFT]
2
Comments
Background On December 1, 2010 the Federal PKI Management Authority (FPKIMA), in compliance with NIST guidance , created a new SHA-256 Federal Common Policy root certification authority. Windows Update will include the new Federal Common Policy Root...
Windows PKI blog
CA manager approval required for certificate re-enrollment
Posted
over 1 year ago
by
Fabian [MSFT]
2
Comments
Hi there, this is Larry, Developer from US, and Fabian, PFE from Germany, writing about an uncommon scenario that might raise questions sometimes. When enrolling certificates to clients or users, you might want to have control regarding the initial...
Windows PKI blog
Quick Check on ADCS Health Using Enterprise PKI Tool (PKIVIEW)
Posted
over 1 year ago
by
Amerk [MSFT]
3
Comments
PKIVIEW was first introduced in Windows Server 2003 Resource kit. The tool is installed by default when you install the Windows 2008 Active Directory Certificate Services Role, and had been re-branded as "Enterprise PKI". The tool is implemented as a...
Windows PKI blog
Verifying The SSL Certificate Expiration with a tool
Posted
over 1 year ago
by
MS2065 [MSFT]
4
Comments
An active member of our community developed a very handy tool to verify - or let's actually say monitor - the validity of SSL server certificates. After downloading and extracting the the ZIP-file the tool is quite self explanatory. Press CTRL+A or click...
Windows PKI blog
Common Questions about SHA2 and Windows
Posted
over 1 year ago
by
Adam Stasiniewicz
1
Comments
Since my last post about SHA2 and Windows I’ve received numerous questions from customers and partners around three particular scenarios. This post will try to address those questions. Windows XP/2003 Enrollment in SHA2 Signed Certificates...
Windows PKI blog
SHA2 and Windows
Posted
over 2 years ago
by
MS2065 [MSFT]
10
Comments
UPDATE (2/8): Based on some recent questions, additional information has been posted about SHA2 and Windows. Introduction We’ve recently received a couple of requests from customers around the functionality of SHA-256 when running on Windows...
Page 1 of 5 (106 items)
1
2
3
4
5