Public Key Infrastructure for Windows Server 2003

Microsoft Public Key Infrastructure (PKI) for Windows Server 2003

Microsoft Public Key Infrastructure (PKI) for Windows Server 2003 provides an integrated public key infrastructure that enables you to secure and exchange information with strong security and easy administration across the Internet, extranets, intranets, and applications. To understand the full value and functionality offered in PKI for Windows Server 2003, read PKI Enhancements in Windows XP Professional and Windows Server 2003.

 

For information about other Windows Server technologies and services, see the complete list of Windows Server 2003 Technology Centers.



On This Page
News and HeadlinesNews and Headlines
Introductory OverviewsIntroductory Overviews
Technical OverviewsTechnical Overviews
Case StudiesCase Studies
Knowledge Base ArticlesKnowledge Base Articles
Step-by-Step GuidesStep-by-Step Guides
Additional ResourcesAdditional Resources
Learn MoreLearn More
Related Technology CentersRelated Technology Centers


News and Headlines

New Reference Book Offers Guidance from Principal Consultant to Microsoft PKI Team

This in-depth reference teaches you how to design and implement even the most demanding certificate-based security solutions for wireless networking, smart card authentication, VPNs, secure e-mail, Web SSL, EFS, and code-signing applications using Windows Server PKI and certificate services.

Update VeriSign Web Server Certificates for IIS Now

VeriSign's old 128-bit Global Server Intermediate Root certification authority certificate for Microsoft Internet Information Services (IIS) and other Web servers expired on January 7, 2004. You should update your servers' certificates to prevent error messages.


Introductory Overviews

Public Key Infrastructure Overview

Learn how Microsoft PKI for Windows Server 2003 can enable you to securely exchange information across the Internet, extranets, intranets, and applications.


Technical Overviews

Windows Server 2003 Advanced Certificate Enrollment and Management

This TechNet white paper covers several remote deployment scenarios and includes step-by-step procedures to perform X.509 certificate enrollment to implement a secure infrastructure.

PKI Enhancements in Windows XP Professional and Windows Server 2003

This white paper introduces Microsoft Windows® XP Professional certificate services and describes enhancements to existing Windows 2000 PKI features. Learn how Microsoft Windows XP Professional and Windows Server 2003 provide an integrated public key infrastructure that enables you to securely exchange information across the Internet, extranets, intranets, and applications.

Designing a Public Key Infrastructure

Microsoft Windows Server 2003 enables a variety of secure applications and business scenarios based on the use of digital certificates. Before you can use digital certificates, however, you need to design a public key infrastructure, which involves planning configuration options for one or more certification authorities, preparing certificates to meet the needs of your organization, and creating a PKI management plan.

Best Practices for Implementing a Microsoft Windows Server 2003 Public Key Infrastructure

This TechNet article describes configuration and deployment best practices for a Windows Server 2003-based PKI.

Windows Server 2003 PKI Operations Guide

This TechNet article describes how to configure and operate a Windows certification authority and includes operational scenarios, custom configuration information, and sample commands.


Case Studies

Covad Communications

Covad managed and authenticated PKI certificates from wireless users and was able to achieve load balancing for virtual private network sessions with remote users by using Microsoft Public Key Infrastructure for Windows Server 2003.

Guardia di Finanza

Italy's Guardia di Finanza implements S/MIME (secure e-mail), EFS (encryption), and IPSec using Microsoft Public Key Infrastructure for Windows Server 2003 and achieves security, reliability, and flexibility.

Northrop Grumman

Northrop Grumman achieved lower total cost of ownership and greater agility by migrating to Microsoft Public Key Infrastructure for Windows Server 2003.

QUALCOMM

To achieve greater security and reliability in its CDMA data services, QUALCOMM is deploying an end-to-end remote access solution based on Microsoft Windows Server 2003 technologies such as Active Directory® directory service, Internet Authentication Service (IAS), and public key infrastructure.


Knowledge Base Articles

Guidelines for Enabling Smart Card Logon with Third-Party Certification Authorities

Learn how to enable smart card logon with Microsoft Windows and a non-Microsoft certification authority.

Requirements for Domain Controller Certificates from a Third-Party Certification Authority

Find out what is required to issue a domain controller certificate from a third-party certification authority.

How to Import Third-Party Certification Authority Certificates into the Enterprise NTAuth Store

Find out how to import certificates issued by third-party certification authorities into the Windows NTAuth store.

How to Enable LDAP Over SSL with a Third-Party Certification Authority

Find out how to enable LDAP over SSL (LDAPS) on a Windows domain controller from either a Microsoft Certification Authority (CA) or a non-Microsoft CA.

Third-Party Certification Authority Support for Encrypting File System

Learn how Windows supports third-party certification authorities that issue Encrypting File System (EFS) certificates and EFS Recovery Agent certificates.


Step-by-Step Guides

Certificate Autoenrollment in Windows Server 2003

Learn about the capability introduced in Microsoft Windows Server 2003 Enterprise Edition, that allows you to automatically enroll users and computers for certificates, including smart card-based certificates.

Best Practices for Implementing a Microsoft Windows Server 2003 Public Key Infrastructure

Use this quick-start guide to set up a Windows Server 2003 public key infrastructure. It provides the information you need to deploy a viable PKI that is based on Windows Server 2003 technology.

Managing a Windows Server 2003 Public Key Infrastructure

Operation and maintenance of a public key infrastructure requires as much planning as for its initial implementation. This paper provides guidance on how to plan for and implement the operation and management of a Microsoft Windows Server 2003 PKI.

Key Archival and Management in Windows Server 2003

This white paper covers best practices for private key archival and management; procedural steps in a key recovery strategy; as well as migration procedures for moving from an Exchange KMS environment to a Windows Server 2003 Certificate Authority.

Planning and Implementing Cross-Certification and Qualified Subordination Using Windows Server 2003

This white paper provides a technical reference and planning guide for PKI administrators who wish to perform PKI cross-certification, deploy bridge Certification Authorities, and understand how to implement qualified subordination in Windows Server 2003.

Step-by-Step Guide to Mapping Certificates to User Accounts

Learn how to map public-key certificates to a Windows user account so that it can be used with Internet Information Services (IIS).


Additional Resources

Advanced Certificate Enrollment and Management

Complex infrastructure and branch-office deployment environments often dictate unique and advanced management techniques for managing a PKI or certificate deployment to remote servers. This white paper explains several remote deployment scenarios along with the step-by-step procedures to perform X.509 certificate enrollment to implement a security-enhanced infrastructure.

Windows Server 2003 PKI Operations Guide

This document provides a guide for administrators on how to configure and operate a Windows certificate authority. Various operational scenarios, custom configuration information, sample commands, and best practices are provided.

Configuring and Troubleshooting Windows 2000 and Windows Server 2003 Certificate Services Web Enrollment

Windows Server 2003 Web enrollment enables certificate enrollment in environments where clients have no direct access to the certification authority. This white paper details the setup, security configuration, and troubleshooting of the Web enrollment component in a distributed network environment.

Implementing and Administering Certificate Templates in Windows Server 2003

This white paper covers best practices in designing, administering, and implementing version 2 Certificate Templates using Windows Server 2003 Enterprise Edition and Enterprise Certification Authorities.

The Windows Server 2003 Family Encrypting File System

Learn how to use the Encrypting File System, a transparent file encryption service provided by the Windows Server 2003 family.

Windows Data Protection

Data protection application programming interface (DPAPI) is used to protect private keys, stored credentials, and other secrets on Windows for both user accounts and machines. This article discusses how to use DPAPI and how DPAPI operates in Microsoft Windows XP and Windows Server 2003.

Certificate Enrollment in Windows CE .NET

Learn about the certificate enrollment process and various options for acquiring a digital certificate for public key-based services and applications in Windows CE .NET.

Adding Revocation Providers to CryptoAPI for Identrus Applications

OCSP, SCVP, and CRLs are some of the prevalent mechanisms to determine the status of certificates. Both OCSP and SCVP are real-time protocols, whereas CRLs are not. This document describes the architecture that can be used to implement a Certificate Validation Trust Provider for the Windows platform that enables it to support one or more of these protocols.


Learn More

Microsoft and VeriSign Teaming Up to Provide Next-Generation Security Solutions for Enterprise Customers

Read this press release to learn how initiatives with Microsoft Windows Server 2003 and VeriSign services will help ease certificate deployment and management for a range of PKI services.


Related Technology Centers

Windows Rights Management Services Technology Center

Visit the Windows Rights Management Services (RMS) technology center, where you'll find introductory and technical overviews, pricing and licensing information, and links to download the RMS components. RMS utilizes Extensible Rights Markup Language (XrML)—an emerging PKI implementation—to provide granular rights expression.

Cryptography and Secure Communications Portal

This Microsoft TechNet portal page provides links to overviews of cryptography, encrypting file system (EFS), PKI, and secure wireless communication, as well as links to product-specific security information.

Top of pageTop of page