A
andy smart
Hi
We're in the process of rolling out VPN access to our network, using
hardware which we were kindly donated. One of the authorisation methods
our hardware will accept is digital certificates. I think this is likely
to be the way to go, for ease of user management as much as anything in
that I can time-limit them (we will want to provide access for short
periods of time only).
I've been reading the MS documentation and I'm not sure if I want to
include the CA server in my domain or not. One of the things that the
docs suggest is that the 'advantage' of this is the it is easy to issue
certificates autmomatically - I actually want to have very tight control
over the people to whom we issue them.
I'd be interested in hearing people's thoughts as to the best practice here.
tia
andy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFBabZZqmlxlf41jHgRAvIdAJ4+RLvnyT3slNjGNtBsGYxFSycMhwCguWQb
DP2Qg1sURKB0DsxvnMHazJE=
=n2R6
-----END PGP SIGNATURE-----
We're in the process of rolling out VPN access to our network, using
hardware which we were kindly donated. One of the authorisation methods
our hardware will accept is digital certificates. I think this is likely
to be the way to go, for ease of user management as much as anything in
that I can time-limit them (we will want to provide access for short
periods of time only).
I've been reading the MS documentation and I'm not sure if I want to
include the CA server in my domain or not. One of the things that the
docs suggest is that the 'advantage' of this is the it is easy to issue
certificates autmomatically - I actually want to have very tight control
over the people to whom we issue them.
I'd be interested in hearing people's thoughts as to the best practice here.
tia
andy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFBabZZqmlxlf41jHgRAvIdAJ4+RLvnyT3slNjGNtBsGYxFSycMhwCguWQb
DP2Qg1sURKB0DsxvnMHazJE=
=n2R6
-----END PGP SIGNATURE-----