Click here to get back home

PKI in multi sites/domains environment

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
PKI in multi sites/domains environment BZP 12-10-2007
Posted by BZP on December 10, 2007, 12:29 pm
Please log in for more thread options
Hello,

First, sorry for my poor english, French NG doesn't answer for my
topic.
I explain my need.
I have an AD forest which looks like this :
A root domain (technical domain, no user account) called ROOT.LOCAL.
I have two domain trees ASIA.LOCAL and AMERICAS.LOCAL.
There are 4 sub-domains called JAPAN.ASIA.LOCAL, CHINA.ASIA.LOCAL (for
ASIA tree) and PERU.AMERICAS.LOCAL and MEXICO.AMERICAS.LOCAL (for
AMERICAS tree).
AD site configuration match name locations.
I want to implemant CA hierarchy like that :

One offline ROOT CA, 2 offline policy CA (one for each location, ASIA
& AMERICAS) and one issuing CA for each domain tree.

1. I want to know how can I be sure that users in ASIA tree will never
ask certificate on CA of AMERICAS tree ? Is it possible ? In technet,
it is specified that CA services (as a forest service) don't use site
informations.

I have several questions too.
(I numbered for easy answers.)

2. Is there one CRL distribution point for a CA or for a CA
hierarchy ?
3. When a client have to check certificate chain, does it established
a network connection with each CA ? Just one ? Any ?
4. Whan I add a CRL distribution point, I have to renew older
certificates ? If I don't, does older certificates still valid ?

I have some difficulties to identify what are the logical and physical
componments in PKI...

Thanks for your help.

Regards,

--
P.J.A.

Similar ThreadsPosted
Smartcard for multi-factor authentication March 2, 2006, 10:01 am
setting up 2-Tier CA Environment July 14, 2005, 3:36 pm
Certs in non-domain environment: January 24, 2008, 12:51 pm
Mixed environment - encryption. July 20, 2008, 2:59 pm
Fine-grained Entitlement Management in SOA Microsoft Environment September 26, 2007, 9:53 pm
machine password expiration in the 2003 domain environment April 14, 2008, 10:57 am
Viewing CMOS\BIOS settings in MS Server 2003 GUI environment June 3, 2006, 3:14 am
Windows Vista Group Policies in a Server 2003 SP1 Domain environment May 11, 2007, 9:21 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap