[Top] [All Lists]

RE: Does Smime works fine with Windows 2000 PKI

2000-05-11 06:44:34
What would happen if you want to open the directory to anonymous access to the 
Web ?
In such a way that you could exchange S/MIME certs with outside people ?

11/05/2000 15:35
To:     Laurent Deffranne/GKBCCB(_at_)GKBCCB
cc:     ietf-smime%imc(_dot_)org(_at_)Internet 

Subject:        RE: Does Smime works fine with Windows 2000 PKI

Let me take the points one at a time and inline:

-----Original Message-----
From: Laurent Deffranne [mailto:Laurent(_dot_)Deffranne(_at_)dexia(_dot_)be]
Sent: Thursday, May 11, 2000 9:19 AM
To: walter.williams
Cc: ietf-smime
Subject: RE: Does Smime works fine with Windows 2000 PKI


Do you mean that there are difficulties to access through LDAP an
Active Directory, as you want to read or use X509 certificates ?

No.  However, are you going to open your active directory to anonymous LDAP
queries over the Internet?  If not, are you limiting S/MIME to internal use
only?  If not then you are somewhat back to square one.

By the way,does somebody know issues about Active Directory LDAP,
or issues to read a certificate in an Active Directory ?

This worked just fine for us here, but the problem we had with AD was that
it does not support inetOrgPerson, and thus can't easily be synched up with
most external LDAP directories.  You'll find you'll want a metadirectory
connector to synch it with any external directory.  Again, this is not an
issue if you're willing to directly expose AD to internet use.

For me it would be a mistake to use now the "brand new" Active
Directory, but if someone could tell me where I can find proofs
of lack of compatibility (from Microsoft, there must be surely
one of two), this would interrest me.

AD seems to work just fine, if you don't mind working with something with a
proprietary schema.  Any LDAP and S/MIME aware client we pointed at it
understood the contents just fine, so the schema does not seem to impact
client interoperability.


11/05/2000 14:54
To:   Laurent Deffranne/GKBCCB(_at_)GKBCCB, 

Subject:      RE: Does Smime works fine with Windows 2000 PKI


Yes, certs issued from a W2K CA can be used for S/MIME, and no
less so than
certs issued from Baltimore, Iplanet or any other CA vendor or
product.  The
main issue is not will they work, but will you be able to validate the
certs.  Unless the person issuing the cert from W2K has provided you with
their server's cert, or they have certified their CA with the signature of
the publicly known CAs you will not be able to easily verify the signature
to its source.  This is not the most technically acurate way of
saying this
but I'm not awake yet.  Baltimore has preregistered there CA with the
vendors distributing products, as has Verisign, Thaught, and many others.
Just make certain that you have the certificates for the W2K CA,
and access
to its revocation list so you can validate properly and you'll be fine.

Walt Williams
Senior IT Analyst

Please note: GTE Internetworking is now Genuity.

-----Original Message-----
From: owner-ietf-smime(_at_)mail(_dot_)imc(_dot_)org
[mailto:owner-ietf-smime(_at_)mail(_dot_)imc(_dot_)org]On Behalf Of Laurent 
Sent: Thursday, May 11, 2000 5:45 AM
To: ietf-smime
Subject: Does Smime works fine with Windows 2000 PKI

Hi everybody,

Just a question :

Is there any known issues using S/MIME with Win2000PKI-certificates ?
More generally, are Win2000 certificates usable with (and
understood by ) the others mailers (especially Lotus Notes,
Netscape, Eudora +plug-in?)

Isn't Baltimore Unicert a "better choice" due to its greater
compatibility ?

Any advices are welcome.


Laurent Deffranne