Pros and Cons of Cross Certification versus using Commercial Certificate ?
hi all,
i considering following options 2 way tls mutual authentication using digital certs applications
1. getting cross certification
2. using commercial certificate
3. issuing cert other party app , getting root ca certificate installed there.
can please give me detailed pros , cons option considering..
1. advantage of cross-certification can define exact parameters of trust. namespace, eku, issuance policies, depth of chain. controlled on side, computers in organization use crossca certificate have defined build certificate chain on app server , implement qualified subordination constraints have defined in cross ca certificate. but, rules enforced domain members download crossca certificate ad.
2. commercial certificate, described in other answer thread, provides best scope of trust. if reputable commercial provider, browsers trust certificate.
3. luck on one. unless own other entity, there no way "get" them install root certificate. there no way if organization.
see presentation on topic (with 3 scenarios discussed)
https://vimeo.com/35053556brian
Windows Server > Security
Comments
Post a Comment