EXERCISE 12.01.E XERCISE 12.03R EQUESTING A C ERTIFICATE FROM A W EB S...

2003.To use this feature, you need to be running either a Windows Server 2003 orWindows XP client and you must log on to a Windows Server 2003 domain. Finally,auto-enrollment must be enabled through Active Directory’s group policy. Also, youwon’t be able to auto-enroll a user unless the user account has been assigned an e-mailaddress.

Q:

What is the default validity period for a new certificate?

A:

The default, which can be changed on the Generaltab of a new template’s propertysheet, is one year. Other important settings, such as minimum key size and purpose ofthe certificate, can be found on the sheet’s other tabs.

Self Test

A Quick Answer Key follows the Self Test questions. For complete questions, answers,and explanations to the Self Test questions in this chapter as well as the otherchapters in this book, see the Self Test Appendix.

Planning a Windows Server 2003 Certificate-Based PKI