Standalone Root- Standalone Sub

Standalone Root- Standalone Sub

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Standalone Root- Standalone Sub Travis 09-13-2005
Posted by Travis on September 13, 2005, 3:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am trying to determing what advantage I will get by implementing a
Standalone Subordinate CA to issue certificates to clients.

I do not have an AD domain and I just need to issue certificates to a
few hundred external vendors. Would it be necessary to have a
subordinate CA or would I be just as well off with a Stand Alone Root
CA issuing the client certs? It would also save me the cost of another
server.

>From what I can tell, I don't get any extra redundancy by having the
sub CA, so what is its intended purpose. Can anyone give an example of
how a sub ca could make sense in my environment?

Thanks!

Travis


Posted by Steven L Umbach on September 13, 2005, 6:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
That is a decision you have to make based on the security needs of your
organization, what PKI is used for, and how important PKI is to it your
existence and reputation. Usually the subordinate is recommended so that the
root CA can be kept offline to protect the integrity of your PKI. The more
complex your PKI structure is and more you and your customers/partners rely
on it the more important it would be to consider an offline CA. If the root
CA is compromised then your whole CA hierarchy that uses that root CA is
compromised. If you have an offline root CA and three issuing subordinates
and one of the subordinate CA's is compromised then only certificates that
subordinate CA issued are compromised. However many organizations use a
single CA for their PKI. Be sure to take steps to protect your CA such as
physically securing it, using hard to guess passwords, disable unneeded
services, enable auditing and monitor the security logs, yada yada so that
unathorized certificates are not issued. --- Steve


>I am trying to determing what advantage I will get by implementing a
> Standalone Subordinate CA to issue certificates to clients.
>
> I do not have an AD domain and I just need to issue certificates to a
> few hundred external vendors. Would it be necessary to have a
> subordinate CA or would I be just as well off with a Stand Alone Root
> CA issuing the client certs? It would also save me the cost of another
> server.
>
>>From what I can tell, I don't get any extra redundancy by having the
> sub CA, so what is its intended purpose. Can anyone give an example of
> how a sub ca could make sense in my environment?
>
> Thanks!
>
> Travis
>



Similar ThreadsPosted
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
Standalone vs Enterprise root CA security. April 8, 2008, 8:13 pm
Standalone CA's and CRL August 27, 2008, 9:10 pm
Standalone/ Enterprise CA issue October 18, 2005, 2:52 am
Restricted groups in a standalone computer October 17, 2006, 12:45 pm
PKI Cert for a website on a standalone server. September 24, 2007, 2:46 pm
Smart Card Authenticatyion to standalone PC January 10, 2008, 7:27 am
standalone CA - cannot use browser to install certs February 1, 2008, 3:41 pm
Clients no longer pick up the Root CA as a trusted root authority June 6, 2006, 6:59 pm
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am

The site map in XML format XML site map

Contact Us | Privacy Policy