How can I create a second certificate authority server for redunda

How can I create a second certificate authority server for redunda

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How can I create a second certificate authority server for redunda Kristina 09-20-2006
Posted by =?Utf-8?B?S3Jpc3RpbmE=?= on September 20, 2006, 12:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We would like to create a second enterprise certificate authority server for
redundancy. How do I that? Thanks.

Posted by Miha Pihler [MVP] on September 20, 2006, 12:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Kristina,

You simply create another one -- just like you did with the first one.
Clients will then see both of them and will contact one or the other.

--
Mike
Microsoft MVP - Windows Security

> We would like to create a second enterprise certificate authority server
> for
> redundancy. How do I that? Thanks.



Posted by Brian Komar [MVP] on September 20, 2006, 7:55 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
news@atlantis.si says...
> Hi Kristina,
>
> You simply create another one -- just like you did with the first one.
> Clients will then see both of them and will contact one or the other.
>
>
There is a little more to this. Are you creating a hierarchy or are you
creating two root CA's within the organization. What is the size of your
organization? What types of certificates are you issuing?

We need more details to tell you how best to deploy the second CA.
Brian

Posted by =?Utf-8?B?S3Jpc3RpbmE=?= on September 21, 2006, 3:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I want to create a root ca, subordinate ca, and then a trust between them. I
have the knowledge base article to do that. Second question, how can I tell
if my CA right now is the "root CA". Where can I tell in the properties?

"Brian Komar [MVP]" wrote:

> news@atlantis.si says...
> > Hi Kristina,
> >
> > You simply create another one -- just like you did with the first one.
> > Clients will then see both of them and will contact one or the other.
> >
> >
> There is a little more to this. Are you creating a hierarchy or are you
> creating two root CA's within the organization. What is the size of your
> organization? What types of certificates are you issuing?
>
> We need more details to tell you how best to deploy the second CA.
> Brian
>

Posted by Brian Komar [MVP] on September 21, 2006, 6:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Kristina@discussions.microsoft.com says...
> I want to create a root ca, subordinate ca, and then a trust between them. I
> have the knowledge base article to do that. Second question, how can I tell
> if my CA right now is the "root CA". Where can I tell in the properties?
>
> "Brian Komar [MVP]" wrote:
>
> > news@atlantis.si says...
> > > Hi Kristina,
> > >
> > > You simply create another one -- just like you did with the first one.
> > > Clients will then see both of them and will contact one or the other.
> > >
> > >
> > There is a little more to this. Are you creating a hierarchy or are you
> > creating two root CA's within the organization. What is the size of your
> > organization? What types of certificates are you issuing?
> >
> > We need more details to tell you how best to deploy the second CA.
> > Brian
> >
>
Wow, you need to start from square one if you are unsure if it is a root
CA... A root CA by definition possesses a self-signed certificate. In
other wordes, the subject and issuer will match in the certificate.

I recommend that you look at the best practices white paper immediately:
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technolog
ies/security/ws3pkibp.mspx

Brian

Similar ThreadsPosted
Local Certificate Authority Server July 7, 2006, 1:53 am
remove certificate authority server September 4, 2007, 4:30 pm
Windows 2000 Certificate Authority (CA) Server - Can I delete Revo April 17, 2006, 9:03 pm
Create certificate with makecert for LDAPS on a DC ? December 11, 2007, 11:10 am
what type of certificate authority? June 16, 2005, 4:08 pm
Certificate Authority type June 16, 2005, 6:01 pm
Problem with certificate authority January 27, 2006, 9:03 am
Certificate Authority (CA) - Failover Possible? February 24, 2006, 8:20 pm
Microsoft Certificate Authority June 14, 2006, 8:25 am
Problem in Certificate Authority February 23, 2007, 4:09 am

The site map in XML format XML site map

Contact Us | Privacy Policy