tailieunhanh - Microsoft Press windows server 2008 Policies and PKI and certificate security phần 5

Bạn chịu trách nhiệm thiết kế mẫu giấy chứng nhận cho tổ chức của bạn. Các bộ phận phát triển phần mềm đã tạo ra nhiều ứng dụng tùy chỉnh đòi hỏi phải có chữ ký điện tử trước khi triển khai mạng. Chữ ký kỹ thuật số được yêu cầu để đáp ứng chính sách bảo mật của công ty về bảo mật ứng dụng tùy chỉnh. | 280 Part II Establishing a PKI Figure 12-12 OCSP Response Signing enables the OCSP No Revocation Checking extension Case Study Certificate Template Design You are responsible for designing certificate templates for your organization. The software development department has created several custom applications that require digital signing prior to network deployment. Digital signatures are required to meet the company s security policy regarding custom application security. The company uses a mix clients running Windows XP and Windows Vista and servers running Windows Server 2003 and Windows Server 2008. Requirements To meet the security policy the manager of the security department has provided you with the following requirements The code-signing certificate must be stored on a Gemalto .NET Base CSP smart card. Only members of the Code Signing group can request a code-signing certificate. All initial code-signing certificate requests are subject to the approval of the company s notary public. Chapter 12 Designing Certificate Templates 281 If you already have a code-signing certificate you can reenroll without having to meet with the notary public again. The code-signing certificate must be valid for four years. The code-signing certificate must never reuse a previous key pair. The code-signing certificate must have a key length of 1 024 bits. Case Study Questions 1. What MMC console do you use to perform certificate template management 2. Does the default Code Signing certificate template meet the design requirements 3. Can you modify the default Code Signing certificate template If not what would you do 4. Should you create a version 2 or a version 3 certificate template 5. In the following table specify the settings on the General tab to meet the design requirements for your custom code-signing certificate template. Attribute Your recommended design Template display name Template name Validity period Publish certificate in Active Directory Do not automatically .

TỪ KHÓA LIÊN QUAN