Activity: Planning Certificate Renewal Settings

An organization named Trey Research has deployed the CA hierarchy illustrated in Figure 10.22.

click to view at full size.

Figure 10.22 The Trey Research CA hierarchy

The Root CA is configured with a certificate validity period of two years, the Division CA has a certificate validity period of five years, and the Department CA has a certificate validity period of three years.

Based on this configuration, answer the following questions. Answers to these questions can be found in the appendix.

  1. What is the longest validity period that can be configured for certificates issued by the Root CA?


  2. What is the longest validity period that can be configured for certificates issued by the Division CA?


  3. What is the longest validity period that can be configured for certificates issued by the Department CA?


  4. What must be done to the validity period of the Root CA to allow the Division CA to issue certificates with a five-year validity period?

Answers



Microsoft Corporation - MCSE Training Kit (Exam 70-220. Designing Microsoft Windows 2000 Network Security)
MCSE Training Kit (Exam 70-220): Designing Microsoft Windows 2000 Network Security: Designing Microsoft(r) Windows(r) 2000 Network Security (IT-Training Kits)
ISBN: 0735611343
EAN: 2147483647
Year: 2001
Pages: 172

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net