multiple CA for same domain ? (a little long..)

multiple CA for same domain ? (a little long..)

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
multiple CA for same domain ? (a little long..) Marco Tonoli 10-24-2006
Posted by =?Utf-8?B?TWFyY28gVG9ub2xp?= on October 24, 2006, 12:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all, i have a question:

i have a PKI infrastructure, with a offline root, an enterprise CA and a
domain controller. We use PKI for smart card, email signing and what future
time will offer...
Now we start a branch office with many user so i make a new domain
controller (for same central domain) in the branch office for autentication
speed and geographics redundance. The lan's have non egual ip addressment but
one see each other. I'll correctly set "site and service" applet so pc remote
will use remote DC.
My question is... i need also a second CA in the branch office ? if not i
can have speed problem ? (i don't kon how fast is connection, specifically
during working hour).

And, if i need a second CA, can install on DC ? (i think have not CPU power
problem and no security access problem) and there same particolar procedure
to avoid strange situation like pc autentication or PKI process on erratic CA
and DC ?

Thanks all in advance (and excuse my english.... writing from italy.)



Posted by S. Pidgorny on October 29, 2006, 4:56 am
If you were  Registered and logged in, you could reply and use other advanced thread options
No, you don't need another CA.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> Hi all, i have a question:
>
> i have a PKI infrastructure, with a offline root, an enterprise CA and a
> domain controller. We use PKI for smart card, email signing and what
> future
> time will offer...
> Now we start a branch office with many user so i make a new domain
> controller (for same central domain) in the branch office for
> autentication
> speed and geographics redundance. The lan's have non egual ip addressment
> but
> one see each other. I'll correctly set "site and service" applet so pc
> remote
> will use remote DC.
> My question is... i need also a second CA in the branch office ? if not i
> can have speed problem ? (i don't kon how fast is connection, specifically
> during working hour).
>
> And, if i need a second CA, can install on DC ? (i think have not CPU
> power
> problem and no security access problem) and there same particolar
> procedure
> to avoid strange situation like pc autentication or PKI process on erratic
> CA
> and DC ?
>
> Thanks all in advance (and excuse my english.... writing from italy.)
>
>



Similar ThreadsPosted
Password too long August 7, 2006, 6:09 pm
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
Error parsing Request: The request subject name is invalid or too long. 0x80094001 (-2146877439) February 27, 2007, 4:01 am
Multiple CA's? January 24, 2008, 1:40 am
multiple Logon permissions April 10, 2006, 4:11 am
Take Ownership of Multiple files at once May 15, 2006, 12:11 pm
Multiple systems logged onto at once January 25, 2007, 8:46 am
CAPICOM: Is it possible to sign multiple files... August 22, 2005, 12:48 pm
Multiple CAs& user auto enrollment June 12, 2006, 4:39 pm
Graceful Shut Down of Multiple Servers from PDC October 19, 2006, 5:14 pm

The site map in XML format XML site map

Contact Us | Privacy Policy