Select the product you need help with
How to make an Enterprise certification authority that is running Windows Server 2003 with Service Pack 1 or an x64-based version of Windows Server 2003 compliant with ISIS-MTT version 1.1Article ID: 890772 - View products that this article applies to. On This PageSUMMARYIf you want to make an Enterprise certification authority (CA) compliant with the ISIS-MTT version 1.1 standard, follow the steps that are described in this article. The issuing CA must force UTF-8 encoding. After a certificate request is submitted, the key usage attribute must be marked "critical" during the certificate submission process. You can then issue and verify the certificate. INTRODUCTIONISIS-MTT is a new German standard for Public Key Infrastructure (PKI) interoperability. ISIS-MTT defines data formats and communication protocols to be employed in interoperable PKI-based applications. ISIS-MTT specifications focus on security services for authentication. These include user identification and data integrity services, confidentiality services, and non-repudiation services. The ISIS-MTT standard was developed by the German government in collaboration with banking, industrial, and academic interests. To make the Microsoft Windows certification authority (CA) compliant with ISIS-MTT version 1.1, you must complete specific configuration steps. This step-by-step article describes how to enroll certificates that comply with the ISIS-MTT requirements for an Enterprise CA. Note Your CA must be a server that is running Microsoft Windows Server 2003 Service Pack 1 (SP1), an x64-based version of Windows Server 2003, or a later version of Windows. Important The configuration changes that are documented in this article must be applied to the CA that enrolls the certificate. In a PKI topology, this is the parent CA of the certificate requester. If a CA certificate is requested from a subordinate CA, the type of CA that requests the certificate is not relevant. Use the step-by-step directions in this article if the following conditions are true:
Enforce UTF8 encodingAfter you configure a CA to force UTF8 encoding, the UTF8 setting applies to all certificates that are issued with this CA. At the CA that must issue ISIS-MTT-compliant certificates, follow these steps:
Configure the certificate template to change the key usage and to mark it as "critical"When certificates are issued with an Enterprise CA, you must set the critical flag through the certificate template that is used for certificate creation. By default, CA certificate requests use the Subordinate Certification Authority certificate template. Certificates for a user or for a computer are processed in one of the following ways:
Request a CA certificate for a subordinate CAIn a multi-tier PKI topology, a subordinate CA can request the CA certificate online or offline. By default, the Subordinate Certification Authority setting is always used when a request is made online. Therefore, the key usage settings are not applied. When a subordinate CA requests the CA certificate, you must complete the request offline so that you can specify the template name.To issue a certificate for a subordinate CA, follow the steps in the "Submit the certificate request" section. Note According to the ISIS-MTT standard, the name of a CA must contain the following distinguished name attributes:
Submit the certificate requestTo enroll a certificate with a specific certificate template, you must set the template name during the certificate submission process by using the Certreq.exe command. To do this, follow these steps:
Technical support for Windows x64 editionsYour hardware manufacturer provides technical support and assistance for Microsoft Windows x64 editions. Your hardware manufacturer provides support because a Windows x64 edition was included with your hardware. Your hardware manufacturer might have customized the Windows x64 edition installation with unique components. Unique components might include specific device drivers or might include optional settings to maximize the performance of the hardware. Microsoft will provide reasonable-effort assistance if you need technical help with your Windows x64 edition. However, you might have to contact your manufacturer directly. Your manufacturer is best qualified to support the software that your manufacturer installed on the hardware.For product information about Microsoft Windows XP Professional x64 Edition, visit the following Microsoft Web site: http://www.microsoft.com/windowsxp/64bit/default.mspx For product information about Microsoft Windows Server 2003 x64 editions, visit the following Microsoft Web site:
(http://www.microsoft.com/windowsxp/64bit/default.mspx)
http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx
(http://www.microsoft.com/windowsserver2003/64bit/x64/editions.mspx)
REFERENCES
For additional information about how to use ISIS-MTT compliant certificates with a stand-alone issuing CA, click the following article number to view the article in the Microsoft Knowledge Base:
888180
(http://support.microsoft.com/kb/888180/
)
How to make a stand-alone certification authority that is running Windows Server 2003 with Service Pack 1 compliant with ISIS-MTT version 1.1
PropertiesArticle ID: 890772 - Last Review: October 11, 2007 - Revision: 2.4 APPLIES TO
|


Back to the top








