CAs: Enterprise root on parent domain, subordinate on child domain

CAs: Enterprise root on parent domain, subordinate on child domain

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
CAs: Enterprise root on parent domain, subordinate on child domain Mark Z. 03-20-2008
Posted by =?Utf-8?B?TWFyayBaLg==?= on March 20, 2008, 10:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We want an infrastructure involving two CAs, an enterprise root CA on the
parent domain and a subordinate CA to do all the work on the child domain.

1. Right now we're decomissioning our Enterprise Root off of the PDC on our
Forest Root domain and want to create a brand new Enterprise Root CA on its
own server.

2. On the child domain we want to build a subordinate CA and do all of the
cert publishing off that box (nothing is on the parent domain which is also
the forest root).

3. After the subordinate CA is set up, we can just power off the Enterprise
root CA, correct? What about security updates?

4. What is the proper setup for this chain to work? Any special
considerations or "gotchas" we need to know about?

Thanks!

Posted by Brian Komar \(MVP\) on March 20, 2008, 11:03 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Almost.,
You want to deploy an offline root CA.
Check out the best practices white paper (www.microsoft.com/pki) or look at
getting a copy of the PKI book from MS Press (several threads on here
referencing it).
You cannot just power off an enterprise CA, as it is a member of the domain.
Only a standalone CA can be powered off as you require.
There are lots of little gotchas discussed in the two sources I provided.
Brian

> We want an infrastructure involving two CAs, an enterprise root CA on the
> parent domain and a subordinate CA to do all the work on the child domain.
>
> 1. Right now we're decomissioning our Enterprise Root off of the PDC on
> our
> Forest Root domain and want to create a brand new Enterprise Root CA on
> its
> own server.
>
> 2. On the child domain we want to build a subordinate CA and do all of the
> cert publishing off that box (nothing is on the parent domain which is
> also
> the forest root).
>
> 3. After the subordinate CA is set up, we can just power off the
> Enterprise
> root CA, correct? What about security updates?
>
> 4. What is the proper setup for this chain to work? Any special
> considerations or "gotchas" we need to know about?
>
> Thanks!


Posted by Paul Adare on March 20, 2008, 11:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Thu, 20 Mar 2008 07:28:04 -0700, Mark Z. wrote:



>
> 3. After the subordinate CA is set up, we can just power off the Enterprise
> root CA, correct? What about security updates?

Then you should be building a standalone root, not an enterprise root. As
far as security updates go, if you treat your standalone root correctly, in
that you never attach it to a network, it doesn't really need regular
updates. I'd suggest that you simply apply any service packs that are
available when you need to start it up to publish a new CRL.

>
> 4. What is the proper setup for this chain to work? Any special
> considerations or "gotchas" we need to know about?

http://www.microsoft.com/pki

http://www.amazon.com/Microsoft-Windows-Server-Certificate-Security/dp/0735620210


--
Paul Adare
MVP - Virtual Machines
http://www.identit.ca
Programming is an unnatural act.

Similar ThreadsPosted
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
Domain Admin can't log into child domains February 15, 2006, 7:19 pm
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
Stand-alone vs Enterprise subordinate CA? March 9, 2007, 12:23 pm
Question on Enterprise Subordinate CA configuration April 2, 2007, 12:21 pm
root ca/subordinate ca October 3, 2007, 9:11 am
Possible conflicting info:Help file states that Offline Root CA canot be member server of domain? January 23, 2007, 5:27 pm
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am
Change from Root CA to Subordinate CA February 2, 2006, 11:36 am
Giving access to a share folder in domain A to users in Domain B May 17, 2007, 2:22 pm

The site map in XML format XML site map

Contact Us | Privacy Policy