AFTER THE KEY PAIR IS GENERATED, THE CERTIFICATE DATABASE SETTINGS...

6. After the key pair is generated, the Certificate Database Settings dialogbox appears. As in Figure 12.6, you will notice that both the certificatedatabase and certificate database log textboxes are already filled withdefault values. You may elect to Store configuration information in ashared folder, but do not check it for purposes of this exercise. ClickNextto complete the installation. After Windows Server 2003 has com-pleted its work (you might be notified during this process that theInternet Information Service (IIS) will stop if you have IIS running onthis machine), click Finish. During the configuration process, you mightbe prompted to insert your Windows Server 2003 installation CD orenter the path to the installation files on the hard disk or on a networkshare. You will also be notified that Active Server Pages (ASP) must beenabled in IIS to provide Web enrollment services. ClickYes to enableASP.

Figure 12.6

Selecting the Certificate Database Location

E

XAM

W

ARNINGPay special attention to the warning given in step 3 in the above exercise. Becausethe distinguished name of the CA is a part of the certificates it issues, renamingthe server or removing it from the domain is not allowed. Windows Server 2003uses the X.500 standard for distinguished names.

Implementing Certification Authorities

EXAM