References & Links
(Thanks to David Cross for the links)
Top Whitepapers:
Default Access Control Settings in Windows Server 2003 whitepaper: https://www.microsoft.com/downloads/details.aspx?FamilyId=2A76C348-FE02-4CB7-9B7A-5A0B9964BD9C&displaylang=en
Internal link to PKI landscape, deployments, challenges, topologies, etc. https://winweb/security/pki/Docs/analysts/Burton/public%20key%20infrastructure_770.pdf
List of new XP and 2003 features: https://www.microsoft.com/technet/prodtechnol/winxppro/plan/pkienh.mspx
Auto-enrollment whitepaper: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/autoenro.mspx
Best Practices for implementing Windows Server 2003 PKI: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws3pkibp.mspx and https://www.microsoft.com/technet/itsolutions/wssra/raguide/Certificate_Services_SB_1.mspx
Microsoft Systems Architecture: https://www.microsoft.com/resources/documentation/msa/2/all/solution/en-us/msa20rak/vmhtm122.mspx
Cross-certification and Qualified subordination whitepaper: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03qswp.mspx
Windows Server 2003 certificate templates whitepaper: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03crtm.mspx
Windows Server 2003 key archival and recovery whitepaper: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/kyacws03.mspx
Guides:
The Secure Access Using Smart Cards Planning Guide : https://www.microsoft.com/technet/security/topics/networksecurity/securesmartcards/default.mspx
Windows Server 2003 PKI operations and configuration guide: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/ws03pkog.mspx
Windows Server 2003 PKI management whitepaper: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/mngpki.mspx
Windows Server 2003 advanced certificate enrollment whitepaper: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/advcert.mspx
Windows Server 2003 web enrollment and troubleshooting guide: https://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/webenroll.mspx
Troubleshooting Certificate Status and Revocation whitepaper: https://www.microsoft.com/technet/security/topics/crypto/tshtcrl.mspx
IPSEC deployment guide: https://www.microsoft.com/technet/security/topics/architectureanddesign/ipsec/default.mspx
MSS wireless guide: https://www.microsoft.com/downloads/details.aspx?FamilyId=CDB639B3-010B-47E7-B234-A27CDA291DAD&displaylang=en
Wireless PEAP guide: https://www.microsoft.com/downloads/details.aspx?FamilyID=60c5d0a1-9820-480e-aa38-63485eca8b9b&displaylang=en
Tutorials and Reference Collection:
Smart Card Mini Driver (a.k.a Card Module) Specification - https://www.microsoft.com/whdc/device/input/smartcard/sc-minidriver.mspx
Windows Vista SDK - https://www.microsoft.com/downloads/details.aspx?familyid=7614FE22-8A64-4DFB-AA0C-DB53035F40A0&displaylang=en
Windows Vista Cryptography Next Generation (CNG) SDK - https://www.microsoft.com/downloads/details.aspx?FamilyId=1EF399E9-B018-49DB-A98B-0CED7CB8FF6F&displaylang=en
This is the overall link to the PKI Technologies collection, which serves as the umbrella introduction to the Certificates, Certificate Services, and CA Certificate Technical Reference sub-collections :
If you want to use links to the individual collections:
EFS is covered in the Data Security collection. The link to the EFS Technical Reference is: https://www.microsoft.com/resources/documentation/WindowsServ/2003/all/techref/en-us/Default.asp?url=/Resources/Documentation/windowsserv/2003/all/techref/en-us/W2K3TR_efs_Intro.asp
Guidelines for Enabling Smart Card Logon with Third-Party Certification Authorities (Q281245): https://support.microsoft.com/default.aspx?scid=kb;en-us;Q281245
- Requirements for Domain Controller Certificates from a Third-Party CA (Q291010): https://support.microsoft.com/default.aspx?scid=kb;en-us;Q291010
How to Import a Third-Party Certificate into the NTAuth Store (Q295663): https://support.microsoft.com/default.aspx?scid=kb;EN-US;Q295663
- Step by Step Guide to Certificate Mapping: https://www.microsoft.com/windows2000/techinfo/planning/security/mappingcerts.asp
How to Enable LDAP over SSL with a Third-Party Certification Authority: https://support.microsoft.com/default.aspx?scid=kb;en-us;321051
Third-Party Certificate Authority Support for Encrypting File System (Q273856 https://support.microsoft.com/default.aspx?scid=kb;en-us;Q273856
Strong Private Key Protection: https://support.microsoft.com/default.aspx?scid=kb;en-us;320828
Enrollment Samples:https://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dncapi/html/certenrollment.asp and https://download.microsoft.com/download/F/1/C/F1C40AF2-8DBE-4F13-B9CA-94F2E0E2DE2F/certificateenrollmentsamples.exe
Win2k info: https://support.microsoft.com/search/default.aspx?Query=windows+2000+eap+tls+computer+authentication
Certificate Services Tools and Settings: https://www.microsoft.com/resources/documentation/WindowsServ/2003/all/techref/en-us/Default.asp?url=/Resources/Documentation/windowsserv/2003/all/techref/en-us/w2k3tr_crtsv_tools.asp
EFS: https://www.microsoft.com/technet/prodtechnol/winxppro/deploy/cryptfs.mspx and https://www.msdn.microsoft.com/library/default.asp?url=/library/en-us/dnsecure/html/WinNETSrvr-EncryptedFileSystem.asp
PKI page: https://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/prodtech/pkitech.asp
Resource kit: https://www.microsoft.com/downloads/details.aspx?familyid=9d467a69-57ff-4ae7-96ee-b18c4790cffd&displaylang=en
Anti-spyware: https://www.microsoft.com/downloads/details.aspx?FamilyID=321cd7a2-6a57-4c57-a8bd-dbf62eda9671
Windows CE: https://msdn.microsoft.com/library/?url=/library/en-us/dncenet/html/certificateenrollment.asp?frame=true
Identrus and OCSP: https://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnsecure/html/rpcrypto.asp
Root Program: https://www.microsoft.com/technet/security/news/rootcert.mspx
Adminpak: https://www.microsoft.com/downloads/details.aspx?FamilyID=c16ae515-c8f4-47ef-a1e4-a8dcbacff8e3&displaylang=en
CSP test suite: https://download.microsoft.com/download/a/9/8/a9831d81-013e-4ba8-a186-18c9133a2cc2/CSPTSTS10.EXE
Vendor Related Info:
Ncipher: https://www.microsoft.com/windows2000/techinfo/administration/security/win2kpki.asp
Chrysalis: https://www.microsoft.com/windows2000/techinfo/planning/chrysalis.asp
Comments
- Anonymous
November 27, 2007
This is an internal link, please remove from the blog post http://winweb/security/pki/Docs/analysts/Burton/public%20key%20infrastructure_770.pdf If the document is for public consumption, then you can upload it to the blog and share it.