Which option is good for SHA-2 in CA?


hi guys,

i have project provide many service public users on web. in project have many server sql server, ntp server, ca server, many dc, iis server, dns server, file server, mail server , etc.

i want supply security structure in internal communications, relation of between iis , sql, or firewall , dc , other anythings.

i think, should have ca structure 3 tier (root ca, policy ca, issuer ca). in opinion, should have policy ca, can extend ca structure in future.

for implement above structure, have big problem selection of sha config in root ca, policy ca , issuer ca. want use sha-2 project. don't know option project.

224 or 256 or 384 or 512 or 512/224 or 512/256?

note: know microsoft ca don't support sha-3 @ now, (that bad, because sha-1 , sha-2 have similar structure).

hi,

>>for implement above structure, have big problem selection of sha config in root ca, policy ca , issuer ca. want use sha-2 project. don't know option project.

224 or 256 or 384 or 512 or 512/224 or 512/256?

microsoft ca support sha-256,sha-384,sha-512.sha-256 popular 1 .sha-512 security. depends on requirements.


best regards
cartman
please remember mark replies answers if help. if have feedback technet subscriber support, contact tnmff@microsoft.com



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client