Designing a Public Key Infrastructure Copyright 2002 Microsoft Corporation. All Rights Reserved. DetailedStepsReviewthedetailedstepscoveredinthedemonstration. Tasks DetailedSteps Important: Perform the following procedures at the computer acting as the enterprise subordinate CA. 1. Log on to the network as Administrator of your domain with a password of password. a. Log on by using the following credentials: User name: Administrator Password: password Log on to: NWTRADERS 2. Inthe Certification Authority console, revoke the following certificates with the Change of Affiliation reason code: • Domain\Certcomp uter (where domain is the NetBIOS name of your domain and computer is the NetBIOS name of your computer) • Domain\Certpartn er (where domain is the NetBIOS name of your domain and partner is the NetBIOS name of your partner’s computer) b. On the Start menu, click Programs, point to Administrative Tools, and then click Certification Authority. c. Inthe console tree, expand computer (where computer is the NetBIOS name of your computer), and then click Issued Certificates. d. Inthe details pane, right-click the certificate with Requester Name of domain\Certcomputer (where domain is the NetBIOS name of your domain and computer is the NetBIOS name of your computer), click All Tasks, and then click Revoke Certificate. e. Inthe Certificate dialog box, inthe Reason code box, select Change of Affiliation, and then click Yes. f. Inthe details pane, right-click the certificate with Requester Name of domain\Certpartner (where domain is the NetBIOS name of your domain and partner is the NetBIOS name of your partner’s computer), click All Tasks, and then click Revoke Certificate. g. Inthe Certificate dialog box, inthe Reason code box, select Change of Affiliation, and then click Yes. Designing a Public Key Infrastructure Copyright 2002 Microsoft Corporation. All Rights Reserved. Tasks DetailedSteps 3. Verify the revoked certificates and publish the CRL. h. Inthe console tree, click Revoked Certificates. Is the task of revoking the certificates complete? No. The CRL must be published to ensure that all certificate-aware applications will see the change inthe status of the certificates. 3. (continued) i. Inthe console tree, right-click Revoked Certificates, and then click Publish. j. Inthe Certificate Revocation List dialog box, click Yes to publish the new CRL. k. Close all open windows and log off the network.