Best Practices for Implementing a Microsoft Windows Server 2003 Public Key Infrastructure
Applies To: Windows Server 2003 with SP1
Note
To download a copy of this document, see https://go.microsoft.com/fwlink/?LinkId=119655.
By David B. Cross and Carsten B. Kinder, Microsoft Corporation
In This White Paper
Creating Certificate Policies and Certificate Practice Statements
Stand-alone Offline Intermediate CA (IntermediateCA1)
Stand-alone Offline Intermediate CA (CorporateSub2CA)
Online Enterprise Issuing CAs (CorporateEnt1CA)
Certification Authority Maintenance
Contents of \\Localhost\CertConfig and \\Localhost\CertEnroll
Relationship of the Configuration Container and Certificate Store
Default CA Certificate and CRL Storage
Mapping Custom Object Identifiers to Friendly Names
CRL Distribution Point Replacement Token
Sample Script to Configure CorporateRootCA
Sample Script to Configure IntermediateCA
Sample Script to Configure the EnterpriseSubCA