Click here to get back home

PKI - Single Offline Root for Multiple Forest

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
PKI - Single Offline Root for Multiple Forest patilp 03-24-2008
Posted by patilp on March 24, 2008, 9:02 pm
Please log in for more thread options
A few questions---

a) Can i have a single PKI hierarchy spanning multiple forests ? Meaning can
a single standalone root CA create certs for issuing / subordinate enterprise
CA's which are located in different AD Forests ?

i am looking for some official guidelines which i can't seem to find anywhere.

i am guessing i can do it by changing the cdp/aia parameters for every CA
cert creation and keep modifying that for a new CA cert. When it’s time to
renew i can put it back. Will this work ?

b) Also most of the docs state that LDAP CDP /AIA entry on the root CA must
be prior to HTTP entry in the list - Is there any specific reason for this
or it doesn't matter.

Thanks in advance for any response.
--
Patilp

Posted by Brian Komar \(MVP\) on March 24, 2008, 11:28 pm
Please log in for more thread options
Inline...

>A few questions---
>
> a) Can i have a single PKI hierarchy spanning multiple forests ? Meaning
> can
> a single standalone root CA create certs for issuing / subordinate
> enterprise
> CA's which are located in different AD Forests ?

Yes, the key is to not use LDAP:/// paths for CDP or AIA extensions. I have
deployed this model quite a few times and only use HTTP:// locations. If
they did have the servers, we could have used a specific LDAP server
(ldap://ldap.example.com/OU=PKI.... )
>
> i am looking for some official guidelines which i can't seem to find
> anywhere.

I am working on a new whitepaper that is going to recommend only using HTTP
URLs if at all possible.

>
> i am guessing i can do it by changing the cdp/aia parameters for every CA
> cert creation and keep modifying that for a new CA cert. When it’s time to
> renew i can put it back. Will this work ?

Actually, you should not have to change anything if you go to HTTP URLs. In
this type of environment, the offline CAs would not use LDAP URLs, so need
to change if you use the default variable names for the certs and CRLs. For
the issuing CAs, it is more of a touchy/feely decision. Where are the
certificates going to be used? If they are localized to that forest, then
you could use LDAP URLs for that issuingCA. If they are used between
forests, I would again, use HTTP alone or as the primary URL.

>
> b) Also most of the docs state that LDAP CDP /AIA entry on the root CA
> must
> be prior to HTTP entry in the list - Is there any specific reason for this
> or it doesn't matter.

Actually, those are much older docs. I personally recommend HTTP first in
all cases. It is more of a universal protocol, and the default LDAP URLs are
only recognized by Windows clients (2000 or later) that are members of the
forest. Unix, non-domain members, etc will fail on the LDAP URL. If it is
the primary URL, this can result in excessive time-outs as it fails on the
LDAP URL. Check out the latest version of the Revocation checking whitepaper
at www.microsoft.com/pki


>
> Thanks in advance for any response.
> --
> Patilp


Posted by patilp on March 25, 2008, 7:53 am
Please log in for more thread options
Excellent / Thanks
--
Patilp


"Brian Komar (MVP)" wrote:

> Inline...
>
> >A few questions---
> >
> > a) Can i have a single PKI hierarchy spanning multiple forests ? Meaning
> > can
> > a single standalone root CA create certs for issuing / subordinate
> > enterprise
> > CA's which are located in different AD Forests ?
>
> Yes, the key is to not use LDAP:/// paths for CDP or AIA extensions. I have
> deployed this model quite a few times and only use HTTP:// locations. If
> they did have the servers, we could have used a specific LDAP server
> (ldap://ldap.example.com/OU=PKI.... )
> >
> > i am looking for some official guidelines which i can't seem to find
> > anywhere.
>
> I am working on a new whitepaper that is going to recommend only using HTTP
> URLs if at all possible.
>
> >
> > i am guessing i can do it by changing the cdp/aia parameters for every CA
> > cert creation and keep modifying that for a new CA cert. When it’s time to
> > renew i can put it back. Will this work ?
>
> Actually, you should not have to change anything if you go to HTTP URLs. In
> this type of environment, the offline CAs would not use LDAP URLs, so need
> to change if you use the default variable names for the certs and CRLs. For
> the issuing CAs, it is more of a touchy/feely decision. Where are the
> certificates going to be used? If they are localized to that forest, then
> you could use LDAP URLs for that issuingCA. If they are used between
> forests, I would again, use HTTP alone or as the primary URL.
>
> >
> > b) Also most of the docs state that LDAP CDP /AIA entry on the root CA
> > must
> > be prior to HTTP entry in the list - Is there any specific reason for this
> > or it doesn't matter.
>
> Actually, those are much older docs. I personally recommend HTTP first in
> all cases. It is more of a universal protocol, and the default LDAP URLs are
> only recognized by Windows clients (2000 or later) that are members of the
> forest. Unix, non-domain members, etc will fail on the LDAP URL. If it is
> the primary URL, this can result in excessive time-outs as it fails on the
> LDAP URL. Check out the latest version of the Revocation checking whitepaper
> at www.microsoft.com/pki
>
>
> >
> > Thanks in advance for any response.
> > --
> > Patilp
>
>

Similar ThreadsPosted
More than one enterprise root CA in a forest? January 18, 2006, 4:13 am
Offline Root CA and CDP/AIA paths August 29, 2005, 8:26 am
Offline Root CA CDP Expiring April 26, 2006, 2:46 am
Publish Offline Root CRL June 3, 2008, 12:07 pm
Publishing offline root in AD and AIA and capolicy.inf July 12, 2005, 11:26 pm
Offline CA Root certificate invisble in AD March 21, 2007, 3:48 pm
Insufficient rights to edit all GPOs in local forest from account in trusted forest. August 15, 2006, 1:21 pm
Firewall setting for multiple FTP sites using multiple ports September 12, 2006, 12:35 pm
Forest Trusts December 6, 2007, 4:03 pm
Migrate Enterprise root authority CA to stand-alone root CA December 13, 2005, 7:57 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap