Happy New Year everyone! I hope everyone had a good set of holidays and is ready to take on the New Year. To start things out in 2008, I’m going to respond to a comment I got from Julie last year. :>)
“But I have to admit, I don’t understand this post. Then again, I’m convinced that only about 10 people on the planet seem to understand crypto. Can you explain a little more about the circumstances where folks would use Windows Certificate Services?”
Ah… Crypto Stuff… My good friend Julie has given me some room to stretch. There is just one problem. To really explain why or where someone would use Windows Certificate Services (or better yet PKI) would take a really serious discussion. Naturally, such a discussion would also need to include benefits, pitfalls, and most likely involve a room full of sleeping people from many different departments within an organization. However, the true problem is where to start the conversation. So, let’s start at the 1,000 meter level…
PKI, in short, is just infrastructure (hence the name Public Key Infrastructure) that accomplishes two primary task. First, it acts as a root of trust for a boat load of “things (technologies)” that use digital certificates. Two, it signs digital certificates (or in some cases also generates keys). That’s it… granted there are some technical things that should be delved into. But, that is not the purpose of this conversation.
The point I’m trying to make is that PKI isn’t technically complex when you look at it from a broad view. I make this statement because it really doesn’t do much. That is why when I talk to my clients, I like to relate PKI to municipal services such public water or electricity. Provided you build it correctly and maintain it “things” can be plugged into it.
So… what are the benefits of implementing a PKI? Well, you benefit from PKI by being able to use the “things” that utilize it to accomplish the two tasks that I previously mentioned. These “things” range from, but not limited to, the following:
- SSL
- IPSEC
- Strong Authentication
- Digital Signatures
- S/MIME
- Encryption
- Code Signing
- Non-reputation
In other words, there are number of technologies/applications that businesses rely on which employ the use of digital certificates. To use these “things” in a sensible manner such that the digital certificates are actually doing their job, it is beneficial (basic IT 101) to plug them into infrastructure that is managed (PKI). The PKI that is used can either be your own, outsourced, or public (Verisign, Thawte, etc.), but the goal is to have some form of manageability and trust associated with it. Otherwise, there is no purpose to using digital certificates at all, or PKI.
Now… now… I know you are all asking. “What about the pitfalls?” Well, I will answer that in my next post.
Lastly, in an act of shameless self promotion, I would like to point out the fact that we are working one an update to the Windows PowerShell Unleashed book. The link for this book just went up on Amazon: Link. As you all might have guessed the book will have 2.0 (CTP) content in it, but we are also making a number of additional changes to address some of the feedback that we got.




