Click here to get back home

Transition from a single enterprise CA to a tiered CA

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Transition from a single enterprise CA to a tiered CA Michael D'Angelo 05-03-2007
Posted by Michael D'Angelo on May 3, 2007, 12:38 pm
Please log in for more thread options
We currently have a single Enterprise Certificate Authority installed on a
domain controller. After reading about best practices, I gather that this
is not really the right way to do it. (Plus I do not like being stuck with
this DC, if we needed to rebuild or remove it.)

I would like to set up an offline standalone root along with one or two
subordinate enterprise CAs. (For the number of certificates we use, I don't
think I need a 3-tier configuration.)

I don't see re-issuing the current certificates by hand to be a problem, but
once the new subordinate enterprise CA is up and running, how can I prevent
new auto-enrolled certificates from using the old CA before I've finished
moving everything? I'm not sure how long decommissioning the old one will
take, and if there is a way to be sure new certificates use the server, that
would help in the transition.



Similar ThreadsPosted
Single login per account possiable? September 28, 2005, 9:07 pm
Looking for Single Computer Two Factor Authentication April 20, 2008, 2:23 pm
How do I block a single IP address from logging on as Administrator? October 31, 2007, 9:39 am
PKI - Single Offline Root for Multiple Forest March 24, 2008, 9:02 pm
Any MS security options for single server 2008 x64 as notebook OS? January 17, 2008, 7:12 pm
Single Server access to stand alone servers within domain June 26, 2008, 6:49 pm
Windows 2003 Single Mode - Workstation Login says: DOMAIN (Win 200 January 10, 2006, 8:41 pm
Modify rights to single file in a directory with only list permiss September 21, 2006, 4:48 pm
enterprise January 30, 2006, 1:46 am
Re: Two Enterprise CAs? July 19, 2007, 2:18 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap