Re: Does Slime works fine with Windows 2000 PKI

2000-05-11 09:26:29

One would think that if you have no control over what is shown and what is not
shown, that you have effectively lost control of your LDAP systems. Which any
outside anyone would love to know, competitors, recruiters, hackers. Just look
at the locator info for some places over the web, you can get info down to the
room number, telephone, wifes name, everything without even trying too hard.
(You just have to be able to type M* to get all names with M in it).

Great fun. I wonder if you could front end the whole thing via HTML/XML so any
request on the LDAP or for S/Mime services would be directed to the web front
end, with the proper controls?

Dan Morrill

Subject:  Re: Does Slime works fine with Windows 2000 PKI

Walter Williams wrote:

Active directory would expose a significant amount of information you might
not want the external world to know, such as a complete listing of all your
w2k computers and their roles in your network.  You could use a LDAP proxy
server to provide what you want to the internet and keep the data in active
directory.  Innosoft (Now purchased by IPlanet) makes such a product.  There
are probably others on the market.

     Would it also disclose the name of all of the
     employees and their roles, something many
     outside recruiters would love to know?

Subject: RE: Does Smime works fine with Windows 2000 PKI

What would happen if you want to open the directory to anonymous
access to the Web ?
In such a way that you could exchange S/MIME certs with outside people ?

Subject:      RE: Does Smime works fine with Windows 2000 PKI

Let me take the points one at a time and inline:

Subject: RE: Does Smime works fine with Windows 2000 PKI


Do you mean that there are difficulties to access through LDAP an
Active Directory, as you want to read or use X509 certificates ?

No.  However, are you going to open your active directory to
anonymous LDAP
queries over the Internet?  If not, are you limiting S/MIME to
internal use
only?  If not then you are somewhat back to square one.

By the way,does somebody know issues about Active Directory LDAP,
or issues to read a certificate in an Active Directory ?

This worked just fine for us here, but the problem we had with AD was that
it does not support inetOrgPerson, and thus can't easily be
synched up with
most external LDAP directories.  You'll find you'll want a metadirectory
connector to synch it with any external directory.  Again, this is not an
issue if you're willing to directly expose AD to internet use.

For me it would be a mistake to use now the "brand new" Active
Directory, but if someone could tell me where I can find proofs
of lack of compatibility (from Microsoft, there must be surely
one of two), this would interrest me.

AD seems to work just fine, if you don't mind working with
something with a
proprietary schema.  Any LDAP and S/MIME aware client we pointed at it
understood the contents just fine, so the schema does not seem to impact
client interoperability.


Subject:    RE: Does Smime works fine with Windows 2000 PKI


Yes, certs issued from a W2K CA can be used for S/MIME, and no
less so than
certs issued from Baltimore, Iplanet or any other CA vendor or
product.  The
main issue is not will they work, but will you be able to validate the
certs.  Unless the person issuing the cert from W2K has
provided you with
their server's cert, or they have certified their CA with the
signature of
the publicly known CAs you will not be able to easily verify
the signature
to its source.  This is not the most technically acurate way of
saying this
but I'm not awake yet.  Baltimore has preregistered there CA with the
vendors distributing products, as has Verisign, Thaught, and
many others.
Just make certain that you have the certificates for the W2K CA,
and access
to its revocation list so you can validate properly and you'll be fine.

Subject: Does Smime works fine with Windows 2000 PKI

Hi everybody,

Just a question :

Is there any known issues using S/MIME with Win2000PKI-certificates ?
More generally, are Win2000 certificates usable with (and
understood by ) the others mailers (especially Lotus Notes,
Netscape, Eudora +plug-in?)

Isn't Baltimore Unicert a "better choice" due to its greater
compatibility ?

Any advices are welcome.


Laurent Deffranne

