Certificate Services

Certificate Services

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Certificate Services =?Utf-8?B?Q2hyaXMgSGlsdG9u?= 09-05-2005
Posted by =?Utf-8?B?Q2hyaXMgSGlsdG9u?= on September 5, 2005, 7:01 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am planning the implementation of PKI and require some advice. I am
currently running a 2003 domain. I would like to setup a hierarcy involving
an offline root CA and an online subordinate CA. I would like the online CA
to be an enterprise subordinate CA utilising AD.

1. Should (or can) the offline root be a stand alone root CA, or should I
install it as an enterprise offline root CA?

2. If I can (and do) install it as an enterprise offline root CA would it be
on a member server or a Domain controller? (if on a DC how will the domain
cope with a DC being offline?)

3. Can the offline CA be installed on a Virtual Server?
--
Chris

--
Chris

Posted by =?Utf-8?B?V29uZyBUdWNrIFdhaA== on September 5, 2005, 10:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
pls see in-line.


> 1. Should (or can) the offline root be a stand alone root CA, or should I
> install it as an enterprise offline root CA?

The root CA be used installed as either SA or Ent. But it is prefered to be
a standalone.


> 2. If I can (and do) install it as an enterprise offline root CA would it be
> on a member server or a Domain controller? (if on a DC how will the domain
> cope with a DC being offline?)

It is never recommended to be installed on a DC, except in a testing ot
training environment. If you bring down your DC, the AD replication will
experience problem with other DCs in the replication ring. So don't ever do
it.

> 3. Can the offline CA be installed on a Virtual Server?

Yes, no problem at all, as long as the guest OS is able to communicate with
the network.

HTH.


Similar ThreadsPosted
Certificate Services August 3, 2005, 12:22 pm
Certificate Services? August 31, 2005, 8:42 pm
Remove Certificate services June 24, 2005, 7:43 pm
Certificate Services Performance --- August 1, 2005, 10:24 am
Certificate Services: Key Archival November 22, 2005, 4:39 am
Moving Certificate Services May 3, 2007, 8:29 am
Difference in Certificate Services June 11, 2007, 5:21 am
Re: Certificate Authority services on W2k forest June 14, 2005, 4:23 pm
Necessity for Certificate Services Web Site October 16, 2006, 3:47 pm
certificate Services will not startup on specified port May 8, 2008, 5:02 pm

The site map in XML format XML site map

Contact Us | Privacy Policy