Solved

Certificate Authority, CA, Windows 2008

Posted on 2014-03-27
7
385 Views
Last Modified: 2014-03-31
hi experts..

please help.
i want to set permission.
only selected people to access the certificate request page.
i checked in the manual, i see that the option is available only for enable and disable authentication in IIS.
i do not see where to link the users id.

Regards,
Skumar.
0
Comment
Question by:Skumar_CCSA
  • 4
  • 3
7 Comments
 
LVL 35

Expert Comment

by:Mahesh
ID: 39961084
What is your exact requirement ?

If you want to grant access certain users to request certificate, you need to control it through Certificate templates in active directory
Certificate templates are available only if you have AD integrated CA installed

Check below link for more information
http://blogs.technet.com/b/askds/archive/2010/05/27/designing-and-implementing-a-pki-part-iii-certificate-templates.aspx
http://btsc.webapps.blackberry.com/btsc/viewdocument.do;jsessionid=7586FB54C3F4697EE3E64F75DDFD9042?externalId=KB27149&sliceId=2&cmd=displayKC&docType=kc&noCount=true&ViewedDocsListHelper=com.kanisa.apps.common.BaseViewedDocsListHelperImpl

Mahesh.
0
 

Author Comment

by:Skumar_CCSA
ID: 39961489
It is standalone Root CA.
No domain
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39961539
I think you have raised another question for same reason, I have posted my comment there to achieve this

If you set IIS rules,and if this server is in workgroup, then you can restrict web site use to local users only

The another way you could do that via restricting TCP port 80 and 443 towards web server via other network segments and this can be achieved through windows firewall rules on server itself or if you have any network firewall between computers and this server
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 

Author Comment

by:Skumar_CCSA
ID: 39961575
Wow.....I am getting more info...
Mahesh can you please help me in giving some links...
The server in domain enviornment, installed standalone Root CA.
Admins will request certificate through URL, issue certificate from CA, and export certificate from cert URL. ( Basically this has been setup for client authentication for non domain laptops.

For restriction.

I logged on windows.
Oped IIS, disabled anonyms access....Enabled Windows authentication, in the edit option I made it enhanced protection with the options of Require.
After doing this I see that when accessing URL from network PC, it ask for usetname and password....but it is not going through even I give the CA server local account.

In this scenario anything settings (either in firewall or IIS level)  that can help to protect the page, it must ask for username and password...and allow post success validation.

Please help ...
Thanks to help ...

Regards,
Skumar.
0
 

Author Comment

by:Skumar_CCSA
ID: 39962001
Hi Mahesh...

Pls help....
Regars,
Skumar
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39962976
Enable basic authentication role service in IIS and then disable windows authentication and anonymous authentication and enable basic authentication on server, default web site and certsrv virtual directory, then it will work by providing username and password

Also you need to directly edit NTFS permissions on IIS certsrv virtual directory, otherwise users who has entered ad username and password will get web page access
U may create AD group with all unwanted user members and provide them deny read permissions on Certsrv virtual directory

OR

You could install URL authorization in IIS role service and then deny permissions to above group from there
http://www.iis.net/configreference/system.webserver/security/authorization

Also you can \ may use windows firewall on certificate server as well to control from which machine can connect to web site

Mahesh
0
 

Author Comment

by:Skumar_CCSA
ID: 39968259
thank you so much
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now