﻿<?xml version="1.0" ?><rss version="2.0"><channel><title>Top Security Solutions from Microsoft Support</title><link>http://support.microsoft.com/ph/1163</link><description>The latest support information about Security Solutions from Microsoft Product Support Services.</description>
<item><title>Certificate Authority fails to start with Event ID 7023</title><link>http://support.microsoft.com/kb/842210#phrss</link><category>Active Directory Certificate Services</category><description>Before Certificate Services starts, it enumerates all the keys and certificates that have been issued to the certification authority (CA), even if the keys and the certificates have expired. Certificate Services will not start if any one of these certificates has been removed from the local computer Personal certificate store.</description></item>
<item><title>Should I use a Standard orEnterprise CA?</title><link>http://social.technet.microsoft.com/wiki/contents/articles/1137.aspx#phrss</link><category>Active Directory Certificate Services</category><description>Learn about the limitations and differences between running a CA on an Enteprise SKU vs a Standard SKU.</description></item>
<item><title>"Access Denied" error when trying to complete a certificate request</title><link>http://support.microsoft.com/kb/278381#phrss</link><category>Active Directory Certificate Services</category><description>The MachineKeys folder stores certificate pair keys for both the computer and users. Both Certificate services and Internet Explorer use this folder. The default permissions on the folder may be misleading when you attempt to determine the minimum permissions that are necessary for proper installation and the accessing of certificates. </description></item>
<item><title>Certificate request template is not correctly configured for a specific application </title><link>http://blogs.technet.com/b/askds/archive/2010/05/27/designing-and-implementing-a-pki-part-iii-certificate-templates.aspx#phrss</link><category>Active Directory Certificate Services</category><description>This is a common support call. Part 3 of the Designing and Implementing a PKI series covers the correct procedure.</description></item>
<item><title>Designing and Implementing a PKI, parts I - V</title><link>http://blogs.technet.com/b/askds/archive/2009/09/01/designing-and-implementing-a-pki-part-i-design-and-planning.aspx#phrss</link><category>Public Key Infrastructure (PKI)</category><description>A 5-part series that covers planning, designing, and deploying a PKI.</description></item>
<item><title>How to configure Security Auditing</title><link>http://technet.microsoft.com/en-us/library/dd408940(WS.10).aspx#phrss</link><category>Authentication and Authorization</category><description>This step-by-step guide demonstrates the process of setting up an advanced Windows 7 and Windows Server 2008 R2 security auditing policy infrastructure.</description></item>
<item><title>Expired Certficate Revocation List (CRL) causes certificate failure during SmartCard logon</title><link>http://blogs.technet.com/b/instan/archive/2008/12/08/requiring-smart-cards-for-logon-avoiding-the-outage-caused-by-expired-crl-s.aspx#phrss</link><category>Authentication and Authorization</category><description>You receive a "Logon failure" message when you use a smart card on a Windows Server-based computer.</description></item>
<item><title>How to use LDAP over SSL (LDAPS)</title><link>http://social.technet.microsoft.com/wiki/contents/articles/2980.aspx#phrss</link><category>Public Key Infrastructure (PKI)</category><description>By default, LDAP communications between client and server applications are not encrypted. If your organizational security policies specify that LDAP communications between client and server computers should be encrypted., this blog post provides the steps to enable LDAP over SSL.</description></item>
<item><title>Certificate enrollment fails with error "No template could be found. There are no CAs from which you have permission to request a certificate, or an error occurred while accessing the Active Directory"</title><link>http://technet.microsoft.com/en-us/library/cc731429(WS.10).aspx#BKMK_5#phrss</link><category>Public Key Infrastructure (PKI)</category><description></description></item>
<item><title>"Recovery policy configured for this system contains invalid recovery certificate" or "ERROR_BAD_RECOVERY_POLICY" error when encrypting a file</title><link>http://technet.microsoft.com/en-us/library/cc738530(WS.10).aspx#BKMK_2#phrss</link><category>Authentication and Authorization</category><description>The Encrypting File System (EFS) recovery policy that is implemented on this computer contains one or more EFS recovery agent certificates that have expired. This TechNet troubleshooting article describes the issue and solution.</description></item>
<item><title>How To Configure Bitlocker backup in Active Directory</title><link>http://technet.microsoft.com/en-us/library/cc766015(WS.10).aspx#phrss</link><category>Bitlocker</category><description>This document describes how to configure Active Directory® to back up recovery information for Windows® BitLocker™ Drive Encryption (BitLocker) and the Trusted Platform Module (TPM).</description></item>
<item><title>Best Practices for Certificate Authority (CA) and Public Key Infrastructure PKI implementation</title><link>http://www.microsoft.com/downloads/en/details.aspx?familyid=6F319FFA-739E-4FE8-BAC3-92547BAEF7A9#phrss</link><category>Public Key Infrastructure (PKI)</category><description>This document provides guidance for the planning and implementation of a Microsoft Windows Server 2008 and Windows Server 2008 R2 public key infrastructure (PKI) using Suite B compliant cryptographic algorithms.</description></item>
<item><title>Events 1925, 1006, 1645, 1055, 40961 on a Windows Server 2008-based domain controller or error message: "No authority could be contacted for authentication" when you use Remote Desktop Connection</title><link>http://support.microsoft.com/kb/939820#phrss</link><category>Authentication and Authorization</category><description></description></item>
<item><title>Unable to logon with Event ID 11, duplicate Service Principal Name registered for client</title><link>http://technet.microsoft.com/en-us/library/cc733945(WS.10).aspx#phrss</link><category>Authentication and Authorization</category><description></description></item>
<item><title>How to Request a Certificate with a Custom Subject Alternative Name</title><link>http://technet.microsoft.com/en-us/library/ff625722(WS.10).aspx#phrss</link><category>Authentication and Authorization</category><description>This guide describes security best practices for allowing custom SANs in certificates and provides procedures that can be used to request a certificate with a SAN.</description></item>
<item><title>KDC Event ID 16 or 27 is logged if DES for Kerberos is disabled</title><link>http://support.microsoft.com/kb/977321#phrss</link><category>Authentication and Authorization</category><description>In Windows 7 and in Windows Server 2008 R2, the Data Encryption Standard (DES) encryption types for Kerberos are disabled by default. This article will help you determine if you need DES encryption in your environment and, if so, how to enable it.</description></item>
</channel></rss>