Skip to main content
Sign In
San Diego Computer & Network Consulting Experts 
Go Search
 
Home
Our Microsoft Expertise
Our Services
Microsoft Solutions Blog
About Gilham Consulting
Contact Us
Support Portal
  

 

z
Home > Gilham Consulting Microsoft Notepad > Posts > Creating a Secure PKI Infrastructure with Microsoft Certificate Services
Creating a Secure PKI Infrastructure with Microsoft Certificate Services

 

PKI Core Roles

  • Enabling strong network user authentication by using smart cards
  • Helping to ensure the confidentiality and integrity of transmitted data by using IPsec
  • Helping to ensure the confidentiality of stored data by using EFS
  • Helping to secure e-mail by using S/MIME encryption and digital signatures
  • Helping to secure Web connections by using SSL or Transport Layer Security (TLS)
  • Helping to facilitate secure relationships with business partners

The common factor for supporting these security technologies was the implementation of a PKI.

...

A Windows Server PKI features:

  • Certificate Services. Certificate Services enables an enterprise to issue and manage X.509 version 3.0 certificates and implement its own PKI.
  • Public key–enabled applications and services. These include Internet Information Services (IIS), Windows Internet Explorer, Microsoft Office Outlook® messaging and collaboration client and Microsoft Outlook Express, EFS, IPsec, and smart card logon.
  • Integration with the Active Directory® directory service. An enterprise can use Active Directory as a publication point for CAs and issued certificates. Active Directory and the account authentication mechanism can also effectively serve as the registration authority, controlling who is able to enroll for what type of certificates based on account credentials.
  • Autoenrollment. An enterprise can use Group Policy to configure automatic certificate enrollment for Active Directory computer account objects.
  • Smart card logon support. An enterprise can use smart cards for interactive logons as well as for certificate and key storage.
  • Public key policies in Group Policy. PKI Group Policy enables administrators to define and control various aspects of PKI use within the domain, including root trust, EFS data recovery, and autoenrollment for computer accounts.

...

Requiring 3 Smart Cards for High Level Security

Microsoft IT created security worlds with administrative card sets composed of six smart cards, any three of which were required to perform administrative functions. The administrative cards were needed whenever a new CA was brought online and added to the associated security world. Two cards were distributed to the Legal and Corporate Affairs department, two others were distributed to a separate internal auditing team, and the final two were retained by the IT Security team in Microsoft IT. The requirement of three smart cards provided role separation and guaranteed that performing such high-level functions required the involvement of members from at least two of these three groups.

Read the whole white paper @> IT Showcase: Deploying PKI Inside Microsoft

Comments

There are no comments yet for this post.
Items on this list require content approval. Your submission will not appear in public views until approved by someone with proper rights. More information on content approval.

Title


Body *


CommentUrl


Attachments

 Latest Reader Comments

OCS 2007 R2 support for SQL 2008 DB mirroringSQL Server 2008 Mirroring in Standard Edition
what about iPhone 4.0?Configuring Exchange Server 2007 ActiveSync for iPhone OS 3.1 (and prior)
CAS Array in Hyper-VHow to setup an Exchange 2010 CAS Array to Load Balance MAPI
Disallow all agents except SharePoint?Useful SharePoint 2007 (MOSS 2007 SEO) configuration with robots.txt file for public facing SharePoint 2007 sites.
Cloud PBXMicrosoft OCS 2010 Is Coming To Unified Communications, PBX Killer
smart cardHow To: Configure Microsoft Remote Desktop Client and Smart Card Authentication
Profiles missing from ImportImporting and Deleting User Profiles in Sharepoint;Filtering Disabled Users from Import; Managing MySite of Deleted Users
Thank youManual Uninstall of SQL 2005 (32bit / 64bit) SQL Server or Express (including Reporting Services)
Auto-deletes all mysites after Full Import ScheduleImporting and Deleting User Profiles in Sharepoint;Filtering Disabled Users from Import; Managing MySite of Deleted Users
PerfectManual Uninstall of SQL 2005 (32bit / 64bit) SQL Server or Express (including Reporting Services)

 Subscribe and Bookmark

 Last 20 Articles

Category
Remote Desktop Connection Manager (RDCMan)
Windows Deployment
 
SharePoint Server 2010 Product Licensing Details
Sharepoint 2010
 
Manage Windows 7 Power Options from the Command Line
Windows Deployment
 
Download details: Windows Phone 7 Training Kit for Developers - April 2010 CTP
Windows Mobile
 
Clustering Remote Desktop Connection (RDC) Broker for High Availability when Deploying Microsoft VDI
Virtualization
 
SharePoint 2010 Reference .Net Software Development Kit (SDK)
Sharepoint 2010
 
Microsoft Private Cloud “AppFabric” Prepares for Release
Cloud Computing
 
Malware and Virus Scanning Architecture in Forefront Threat Management Gateway (TMG) 2010
Security
 
Best Practices Analyzer (BPA) for HYPER-V (RTM and R2)
Virtualization
 
Microsoft Threat Management Gateway (TMG) 2010 - Key Features & Capabilities
Security
 
The forecast is sunny for [Microsoft] cloud services.
Cloud Computing
 
Microsoft announces "RemoteFX," the Calista-based Hyper-V-requiring PC-over-IP competitor
Virtualization
 
Dynamic Memory (aka Memory Overcommit) Coming To Hyper-V
Virtualization
 
SharePoint Overwhelms Business Intelligence - Gartner
Sharepoint 2010
 
Active Directory Power Tool: AD Explorer (and Editor)
Active Directory
 
Protect your Business Information for Free using Encrypting File System (EFS)
Security
 
How to: Integrate Office Communications Server (OCS) 2007 R2 with Exchange 2010 OWA/CAS
Exchange 2010
 
Microsoft Forefront Identity Manager (FIM) 2010 Released
Security
 
Microsoft Thinks VDI Might Not be the Answer to Every Desktop Scenario
Windows Deployment
 
Creating Hyper-V Virtual Machine Templates for VDI or SCVMM Library
Virtualization
 


Contact Us  |   San Diego, California

Copyright 2007-2009 Gilham Consulting - All rights reserved