security - Communication Between MS 2003 CA Server and Client - Non active directory environment :Design Query -
I have a scanner where CA and its clients are not in the active directory environment (win 2003 Enterprise). They are physically located in different (different places). For example,
* If the domain name is 'exampleBank.org' * * * CA name is 'ca'. ExampleBank.org '* * CA Type Enterprise Root CA (Online) [Windows 2003 Enterprise Server] *
- How certificates / CRLs will be distributed by CA non-Active Directory Atmosphere?
- How will the client send their CSR to CA?
- Can the ICARTQ2ST2 interface be useful under this type of scanner for sending CA's requests? (Send call)
- Do I need to look at the LDAP approach?
-
CA will publish a certificate in a public server or LDAP server . Therefore the certificates should be delivered through those URLs. From time to time, the C50 will be published in the X509 certificate at the place point indicated by the area.
-
The CSR can be manually moved to the registration authority (if CA is one) or this interface will be defined by CA
-
I think, this interface is RPC based, so it must be valid only in one network. Can anyone explain this point?
thanks
Comments
Post a Comment