PIX and Windoes CA Server, 7.x work with Enterprise CA?

Years and years ago, I managed to get my Pix to talk to my Windows 2000 Standalone CA Certificate Server with the help of MSCEPCA. All the IPSec VPN Clients enrolled with the Standalone CA, got a Cert and were able to log into the PIX and get access.

I cant remember why, but it would only work with the Standalone CA Server and not the Enterprise CA Server.

Does anyone know if that has changed? We have a Windows 2008 Enterprise CA and it would be nice to have just the one CA to maintain.

If so, what's the best way to transition the clients and remote end points to use the new CA?

Thanks, Scott

Reply to
Scott Townsend
Loading thread data ...

As far as I know, the security model is still the same; one root CA and at least one issuing CA.

If you can import the old root CA somehow then it might ease the transition. Otherwise, you'll need to reissue everyone's certs.

-Gary

Reply to
Gary

I guess I should have been more clear.

on a Win2K/Win2K3 Server you could only use a Standalone Root CA with the SCEP Add-on in order for the CA to allow users to enroll and get a Cert that the PIX could use. You could not use an Enterprise Root CA. (AD Integrated)

Though that was with v6 of the PIX OS. Does v7, allow you to get around the need to use SCEP and or a Standal>

Reply to
Scott Townsend

That I don't know. My use of MS's CA infrastructure is in conjunction with IAS/RADIUS and Cisco WLAN controllers. We're using it because it integrates well with AD. Are you using certs for IPsec VPN authentication? You might try posting to one of the Microsoft specific groups like microsoft.public.windows.server.security or microsoft.public.internet.radius.

There may be a CA specific group on their web fora now, too, but I haven't looked in some time. The folks that read the radius group seem to be familiar with cert issues, too.

-Gary

Reply to
Gary

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.