tailieunhanh - Microsoft Press mcsa mcse self paced training kit exam 70 - 293 phần 7
Khi tạo một cơ sở hạ tầng CA cho tổ chức của bạn, bạn phải quyết định có bao nhiêu CA bạn cần, ai sẽ là người cung cấp cho họ, nơi để xác định vị trí, và những gì các mối quan hệ tin cậy giữa chúng. Bạn có thể sử dụng CA nội bộ chạy trên máy tính của riêng bạn hoặc CA chuyên nghiệp bên ngoài vided bởi một dịch vụ thương mại | 11-12 Chapter 11 Creating and Managing Digital Certificates When creating a CA infrastructure for your organization you must decide how many CAs you need who is going to provide them where to locate them and what the trust relationships between them should be. Using Internal or External CAs You can use either internal CAs running on your own computers or external CAs provided by a commercial service for all your certificate needs. Some applications such as software code signing clearly call for one or the other but in many cases the choice depends on the needs and capabilities of your organization. The advantages and disadvantages of using internal and external CAs are summarized in Table 11-2. Table 11-2 Advantages and Disadvantages of Internal and External CAs Advantages of an Internal CA Disadvantages of an Internal CA Advantages of an External CA Disadvantages of an External CA Direct control Increased certificate Instills customers with High cost per certificate over certificates management overhead greater confidence in the organization No per-certificate Longer more com- Provider liable for PKI No autoenrollment fees plex deployment failures possible Can be integrated into Active Directory Organization must accept liability for PKI failures Expertise in the technical and legal ramifications of certificate use Less flexibility in configuring and managing certificates Allows configuring and expanding PKI for minimal cost Limited trust by external customers Reduced management overhead Limited integration with the organization s infrastructure In many cases organizations use a combination of internal and external CAs. They use their own CAs to secure their internal communications and use external CAs when they must secure communications with outside parties such as customers. How Many CAs If you decide to use internal CAs for your network the next step is to determine how many CAs you need and where to locate them. A single CA running on Windows Server 2003 can
đang nạp các trang xem trước