Certificate Services

Windows 2000’s Public Key Infrastructure (PKI) manages public-key encryption. This type of encryption uses two keys: a public key and a private key. Messages encrypted with the private key can be decrypted with the public key, and vice versa.

Windows 2000 Certificate Services manages the issuing of certificates. These are documents that verify identity and can include a public/private key pair. Certificates are issued by a certificate authority (CA). There are several types of CA:

Standalone root CA

Standalone CAs are used when the organization will be issuing certificates to third parties. The root CA is the most trusted CA and can authorize subordinate CAs. Standalone CAs do not require Active Directory.

Standalone subordinate CA

Standalone subordinate CAs are authorized by and subordinate to the root CA.

Enterprise root CA

Enterprise CAs are used when the organization will be issuing certificates internally, i.e., to employees or students. The enterprise root CA is the highest authority and can authorize subordinate CAs. Windows 2000 allows one enterprise root CA per certificate hierarchy and any number of root CAs per network. Enterprise CAs require Active Directory.

Enterprise subordinate CA

Enterprise subordinate CAs are authorized by and subordinate to the root CA.

Installing a Certificate Authority

You can configure a certificate authority on any Windows 2000 Server computer. Follow these steps to install a CA:

  1. In the Control Panel, select Add/Remove Programs, then select Add/Remove Windows Components.

  2. Check the Certificate Services option.

  3. You are warned that the computer cannot be renamed or removed from the domain; click OK.

  4. Select the CA type from the four types listed in the previous section.

  5. Enter the name, organization, city, and other details for the CA and click Next.

  6. Specify a directory for the CA database. The default is C:WINNTSystem32CertLog. Click Next.

  7. The CA is now installed; this may take several minutes, and the Windows 2000 CD-ROM may be required.

Managing Certificates

The Windows 2000 Certificate Authority can be managed using the Certificate Authority Manager MMC snap-in, available from the Administrative Tools menu after installation. There is also a web-based interface for enrolling certificates. Various certificate management tasks are described in the following sections.

Requesting a certificate

The process of requesting and being granted a certificate is called enrollment. Follow these steps to request and grant a certificate:

  1. With a web browser, connect to http://servername/certsrv/default.asp.

  2. Select the Request a Certificate option and click Next.

  3. In the Certificate Authority Manager, select Pending Requests in the left pane.

  4. Right-click the pending request and select Issue.

  5. In the browser, access the same URL. Select the Check on a pending certificate option and click Next.

  6. You can now view and use the certificate.

Revoking a certificate

Occasionally, you may need to revoke an issued certificate. To revoke a certificate, highlight it in Certificate Authority Manager, right-click, and select Revoke Certificate. You are prompted for a reason for the revocation.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
13.58.209.201