Re: Serwer certyfikatów 2003 nie przydziala - dla ekspertów

Autor: Jacek Marek <no.spam_jmarekw_at_interia.pl>
Data: Tue 01 Mar 2005 - 11:17:43 MET
Message-ID: <d01fj0$gkg$1@diplo.bci.pl>

Aleks wrote:
> Co to może być?
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/kyacws03.mspx#EEAA

Migrating Exchange KMS to Windows Server 2003 CA
The following are the summary steps for migrating Exchange 2000 Server KMS
to a Windows Server 2003 Certificate Authority.

1. If running Exchange 5.5 KMS, upgrade to Exchange 2000.
2. Configure Windows Server 2003 CA for key archival.
(Czy aby przypadkiem "key archival" nie ma tylko Enterprise 2003, Data
Center Server?)
3. Ensure that the certificate is available for database migration.
4. Enable the foreign certificate import option on the CA, if necessary.
5. Export the Exchange KMS database.
6. Import the Exchange database into the CA.

Important: Before migrating KMS to a Windows Server 2003 CA, it is important
to consider the version 1 CRL that is published by the Exchange KMS for
Outlook clients in the Exchange Global Address List (GAL). If KMS is
migrated to a Windows Server 2003 CA, the v1 certificates can no longer be
revoked and it is recommended that a KMS migration is only performed when
all V1 certificates are expired and/or are no longer being issued by KMS. If
x.509 version 3 certificates are being issued by KMS with a Windows 2000 CA,
the existing CA will need to be maintained to publish CRL(s) until all the
original certificates issued by KMS have expired.

JM
Received on Tue Mar 1 11:20:23 2005

To archiwum zostało wygenerowane przez hypermail 2.1.8 : Tue 01 Mar 2005 - 11:42:01 MET