Cain Manor

Your Guide To All Things Cain™

Windows Certificate Management (SSL)

This is an effort to avoid some of the prob­lems with Cer­tifi­cate Man­age­ment, espe­cially as they relate to SSL and Secure LDAP. I will update this as I find out more information.

Terms

Cer­tifi­cate Author­ity — The Server that is gen­er­at­ing Cer­tifi­cates. This could be an inter­nal Cer­tifi­cate Author­ity (gen­er­ally Microsoft) or an exter­nal firm such as VeriSign (the largest CA ven­dor)
SSL — Secure Socket Layer
TLS — Microsoft’s imple­men­ta­tion of SSL, embraced and extended.


A microsoft certificateFrom your Domain Con­troller start MMC -

add “Cer­tifi­cates” snap-in
select “com­puter account.” You have a choice of “my User Account”, “Ser­vice Account” or “Com­puter Account.” We are set­ting this up for the com­puter.
“Local Com­puter“
Fin­ish
Close
OK

Find your Cer­tifi­cates in the Console

Select “Trusted Root Cer­ti­fi­ca­tion Author­i­ties.” Under­neath “Cer­tifi­cates” you will find many cer­tifi­cates (232-ish on a default install.) One of those will be the cer­tifi­cate (Pro­duc­tion Root CA) that allows you to trust the CA that gen­er­ates the cer­tifi­cates for you.

Select “Per­sonal.” Under­neath “Cer­tifi­cates” you should find very few cer­tifi­cates. If you click the one issues by your CA, you can see who it is issued to, who it is issued by and, most impor­tantly, the dates this cer­tifi­cate is valid.

If you are deal­ing with Win­dows 2003 Domain Con­troller and a Win­dows CA set up to auto gen­er­ate Cer­tifi­cates, about two weeks before your cer­tifi­cate expires, the Domain Con­troller will request a new cer­tifi­cate — if you use autoen­rolle­ment. How­ever, the DC can­not use this cer­tifi­cate until it reboots. What this really means is that you have to reboot your DC within two weeks of your cer­tifi­cate expir­ing or it will stop answer­ing SSL traffic.

Out­stand­ing Questions

How do you set up your DC to look to the CA? Is it as sim­ple as adding the cer­tifi­cate to “Trusted Root Cer­tifi­cate Author­i­ties?“
Can you expand the win­dow in which your DC down­loads a new cer­tifi­cate?
Can you force an on-demand down­load of a new certificate?

More infor­ma­tion can be found HERE

Comments are closed.