CAPolicy.inf vs Certutil
hi,
according technet:
a capolicy.inf file not required install ad cs or renew ca certificate. file needed modify default settings (http://technet.microsoft.com/en-us/library/cc775815%28v=ws.10%29.aspx).
however, can 'default settings' not modified after installation using certutil.exe command instead? mean don't need capolicy,inf file?
thanks,
sk
hi,
the capolicy.inf file used during ca key generation or important key renewal, e.g. key length, new validity period, or starts ca without using default templates. settings can make certutil.exe have affect on certificates issued ca or on behavior of ca, e.g. max certificate validity period, encryption csp. right settings, e.g. cdp, aia or crl validity overlapping between two.
hope helps,
lutz
Windows Server > Security
Comments
Post a Comment