<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Windows PKI blog : whitepaper</title><link>http://blogs.technet.com/pki/archive/tags/whitepaper/default.aspx</link><description>Tags: whitepaper</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Certificate Revocation Checking Whitepaper</title><link>http://blogs.technet.com/pki/archive/2009/11/07/certificate-revocation-checking-whitepaper.aspx</link><pubDate>Sat, 07 Nov 2009 23:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292202</guid><dc:creator>Yogesh Mehta</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/pki/comments/3292202.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=3292202</wfw:commentRss><description>&lt;P&gt;A whitepaper on Certificate Revocation Checking in Windows Vista and Windows Server 2008 has been publshed&amp;nbsp;on Technet here - &lt;A href="http://technet.microsoft.com/en-us/library/ee619730(WS.10).aspx" mce_href="http://technet.microsoft.com/en-us/library/ee619730(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/ee619730(WS.10).aspx&lt;/A&gt;&lt;/P&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: SimSun; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-font-kerning: 12.0pt"&gt;
&lt;P style="MARGIN: 3pt 0in" class=MsoNormal&gt;Topics in this whitepaper include:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;What’s new in Windows Vista and Windows Server 2008 revocation checking&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;How revocation checking works&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;How pre-fetching revocation information improves performance&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Support for independent OCSP signer and custom OCSP URLs&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Recommendations for optimizing the revocation experience&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Managing OCSP Settings with Group Policy&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in 3pt 0.25in; mso-list: l0 level1 lfo1" class=BulletedList1&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in" class=MsoNormal mce_keep="true"&gt;You can&amp;nbsp;also download a copy of the paper here - &lt;A href="http://go.microsoft.com/fwlink/?LinkId=145008" mce_href="http://go.microsoft.com/fwlink/?LinkId=145008"&gt;http://go.microsoft.com/fwlink/?LinkId=145008&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in" class=MsoNormal mce_keep="true"&gt;The content also applies to Windows 7 and Windows Server 2008 R2.&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in" class=MsoNormal&gt;Please let me know if you have questions/feedback: &lt;A href="mailto:ymehta@microsoft.com"&gt;ymehta@microsoft.com&lt;/A&gt; &lt;/P&gt;
&lt;P style="MARGIN: 3pt 0in" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292202" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/whitepaper/default.aspx">whitepaper</category><category domain="http://blogs.technet.com/pki/archive/tags/certificates/default.aspx">certificates</category><category domain="http://blogs.technet.com/pki/archive/tags/CRL/default.aspx">CRL</category><category domain="http://blogs.technet.com/pki/archive/tags/OCSP/default.aspx">OCSP</category><category domain="http://blogs.technet.com/pki/archive/tags/revocation/default.aspx">revocation</category></item><item><title>Cross-forest Certificate Enrollment with Windows Server 2008 R2 Beta</title><link>http://blogs.technet.com/pki/archive/2009/01/20/cross-forest-certificate-enrollment-with-windows-server-2008-r2-beta.aspx</link><pubDate>Tue, 20 Jan 2009 10:37:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3186362</guid><dc:creator>MS2065</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/pki/comments/3186362.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=3186362</wfw:commentRss><description>&lt;p&gt;I am excited to announce the public availability of the &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d408be72-7c74-4b19-a2de-fa11858c30b2&amp;amp;DisplayLang=en"&gt;Cross-forest Certificate Enrollment with Windows Server 2008 R2 Beta&lt;/a&gt; whitepaper.&lt;/p&gt; &lt;p&gt;The product team worked hard to make this break through functionality happen in &lt;a href="http://www.microsoft.com/windowsserver2008/en/us/R2.aspx"&gt;Windows Server 2008 R2&lt;/a&gt; beta. Now is the time to evaluate cross forest certificate enrollment in your test environment. If you have specific feedback on the whitepaper, feel free to add you comments to this blog entry.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;From the abstract:&lt;/strong&gt;&lt;br&gt;Windows Server 2008 R2 Beta allows enterprises to issue digital certificates from an enterprise Certification Authority (CA) to the clients that are members of a different Active Directory (AD) forest. This process is called cross-forest certificate enrollment. This white paper will explain how the cross-forest certificate enrollment works. It will also provide deployment guidance for new and existing Active Directory Certificate Services (ADCS) deployments. The paper will cover strategies for consolidating existing certificate templates that may be already in use in the enterprise. It will present choices for ongoing management of the cross-forest certificates deployment. A PowerShell script is also provided to facilitate management tasks related to setting up and maintaining cross-forest certificate enrollment environment.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3186362" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/whitepaper/default.aspx">whitepaper</category></item><item><title>New Windows Biometric Framework and Driver Model</title><link>http://blogs.technet.com/pki/archive/2009/01/14/new-windows-biometric-framework-and-driver-model.aspx</link><pubDate>Wed, 14 Jan 2009 21:41:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3182513</guid><dc:creator>MS2065</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/pki/comments/3182513.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=3182513</wfw:commentRss><description>&lt;p&gt;Those of you who are interested in biometrics should look at the following documents:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/WBFIntro.docx"&gt;Introduction to the Windows Biometric Framework (WBF)&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://download.microsoft.com/download/5/E/6/5E66B27B-988B-4F50-AF3A-C2FF1E62180F/COR-T611_WH08.pptx"&gt;New Windows Biometric Framework and Driver Model&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a href="http://www.microsoft.com/whdc/devtools/WDK/default.mspx#win7wdk-beta"&gt;Windows 7 Beta WDK&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3182513" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/whitepaper/default.aspx">whitepaper</category></item><item><title>New whitepapers about Windows Server 2008 Certificate Services</title><link>http://blogs.technet.com/pki/archive/2008/05/25/new-whitepapers-about-windows-server-2008-certificate-services.aspx</link><pubDate>Sun, 25 May 2008 22:04:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3060910</guid><dc:creator>MS2065</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/pki/comments/3060910.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=3060910</wfw:commentRss><description>&lt;p&gt;&lt;font face="Lucida Sans Unicode" color="#008080" size="2"&gt;This blog-entry has two purposes:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Lucida Sans Unicode" color="#008080" size="2"&gt;1) make you aware of the two new whitepapers that have been just released:&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/fa3eca63-3eda-418e-b469-5c6865bd0d2e1033.mspx"&gt;Active Directory Certificate Services Upgrade and Migration Guide&lt;/a&gt; &lt;li&gt;&lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/fcb66b2a-2d32-405f-9ed1-b10d27e424c31033.mspx"&gt;Configuring and Troubleshooting Certification Authority Clustering in Windows Server 2008&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font face="Lucida Sans Unicode" color="#008080" size="2"&gt;2) provide you a feedback channel. If you have comments about these two papers or any other PKI whitepapers please add a comment to this entry and we will see if we can fix the document.&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3060910" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/whitepaper/default.aspx">whitepaper</category></item><item><title>Configuring and Troubleshooting Certificate Services Client–Credential Roaming</title><link>http://blogs.technet.com/pki/archive/2006/12/18/configuring-and-troubleshooting-certificate-services-client-credential-roaming.aspx</link><pubDate>Mon, 18 Dec 2006 23:53:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:561806</guid><dc:creator>MS2065</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/pki/comments/561806.aspx</comments><wfw:commentRss>http://blogs.technet.com/pki/commentrss.aspx?PostID=561806</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 0pt"&gt;&lt;FONT face="Lucida Sans Unicode" color=#31849b&gt;After a long waiting time the Certificate Services Client credential roaming whitepaper got published at &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/guidance/cryptographyetc/client-credential-roaming/terminology-assumptions.mspx"&gt;&lt;FONT face="Lucida Sans Unicode"&gt;http://www.microsoft.com/technet/security/guidance/cryptographyetc/client-credential-roaming/terminology-assumptions.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT color=#31849b&gt;&lt;FONT face="Lucida Sans Unicode"&gt;.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=561806" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/pki/archive/tags/whitepaper/default.aspx">whitepaper</category></item></channel></rss>