Enterprise Resource Security Mastering Cryptographic Key Lifecycles

Can AD CS continue to be used while only MTG CLM is integrated?

Yes, your existing Microsoft Active Directory Certificate Services (AD CS) can continue to operate while MTG CLM is integrated. The Microsoft CA remains the issuing Certification Authority, while MTG CLM adds centralized certificate management, transparency, and automation capabilities.

Active Directory Access – How can I secure access to AD when using MTG PKI?

Protecting access to Microsoft Active Directory is important when MTG PKI is integrated with an AD environment. Appropriate security measures include: VPN (Virtual Private Network): Use encrypted network connections to protect administrative and system access. Multi-Factor Authentication (MFA): Require additional authentication factors for privileged and administrative access. Network Access Control (NAC): Control network access based […]

OCSP – Can an Online Responder (OCSP) be used securely with Microsoft AD CS?

Yes, Microsoft AD CS environments can use Online Responders for OCSP. As with any security-critical PKI component, however, the architecture and administrative separation of CAs, revocation services, and Active Directory must be carefully designed. Potential risks can arise when CA, OCSP, CRL, and administrative systems share the same trust boundaries, privileged accounts, or infrastructure. Security […]

NDES – What challenges are associated with NDES and what limitations should be considered?

The Network Device Enrollment Service (NDES) extends Microsoft AD CS with SCEP support, but there are several architectural and operational considerations: Policy configuration: NDES configurations are closely tied to specific CA, certificate template, and enrollment settings, which can increase administrative complexity. Additional infrastructure: Depending on the required separation of use cases, additional NDES or Windows […]

AD CS Interface Support – Does AD CS support common interfaces for modern PKI requirements?

Active Directory Certificate Services (AD CS) primarily uses Microsoft-specific enrollment mechanisms such as RPC/DCOM and MS-WCCE. These interfaces are closely tied to Microsoft and Active Directory environments and are less suitable for many cloud-native and heterogeneous use cases. SCEP can also be provided in Microsoft environments through NDES, but this requires additional infrastructure and configuration. […]

PKI Migration – Can I keep my existing Active Directory processes when changing PKI platforms?

Yes, with the CLM Autoenrollment Connector, you can continue to use established Microsoft autoenrollment processes when migrating from Microsoft AD CS to MTG Corporate PKI. The Connector integrates MTG Corporate PKI into the existing Microsoft Active Directory environment and enables automated certificate request, renewal, and deployment through established Windows mechanisms. The specific migration effort depends […]

Certificate Policies – Can policy modules be created with AD CS?

Yes, Microsoft AD CS supports policy modules. However, the standard Windows policy module provides only limited flexibility for defining detailed validation rules for certain certificate request scenarios. This can increase the risk of incomplete or incorrectly structured certificate requests if additional controls are not implemented. A modern PKI and CLM solution such as MTG Corporate […]

Availability – Does the Microsoft PKI Certification Authority remain continuously available during configuration changes?

Some configuration changes to a Microsoft Certification Authority require the CA service to be restarted. During this restart, the Certification Authority is temporarily unavailable. This can be relevant in environments where the CA is frequently used or where configuration changes must be performed during normal business operations. Modern PKI platforms can provide more flexible approaches […]

Certificate Templates – Can certificate templates be used with Active Directory?

Yes, certificate templates are stored in Active Directory. However, there are several limitations to consider: Automation of template creation and modification: There is no standard built-in workflow for fully automating the creation and modification of certificate templates, which means changes often require administrative intervention. Centralized configuration: Certificate templates are centrally available within the Active Directory […]

WordPress Cookie Plugin by Real Cookie Banner