security - Communication Between MS 2003 CA Server and Client - Non active directory environment :Design Query -


I have a scanner where CA and its clients are not in the active directory environment (win 2003 Enterprise). They are physically located in different (different places). For example,

  * If the domain name is 'exampleBank.org' * * * CA name is 'ca'. ExampleBank.org '* * CA Type Enterprise Root CA (Online) [Windows 2003 Enterprise Server] *  
  1. How certificates / CRLs will be distributed by CA non-Active Directory Atmosphere?
  2. How will the client send their CSR to CA?
  3. Can the ICARTQ2ST2 interface be useful under this type of scanner for sending CA's requests? (Send call)
  4. Do I need to look at the LDAP approach?
    1. CA will publish a certificate in a public server or LDAP server . Therefore the certificates should be delivered through those URLs. From time to time, the C50 will be published in the X509 certificate at the place point indicated by the area.

    2. The CSR can be manually moved to the registration authority (if CA is one) or this interface will be defined by CA

    3. I think, this interface is RPC based, so it must be valid only in one network. Can anyone explain this point?

    thanks


Comments

Popular posts from this blog

c++ - Linux and clipboard -

What is expire header and how to achive them in ASP.NET and PHP? -

sql server - How can I determine which of my SQL 2005 statistics are unused? -