Enterprise Root CA
hi
i wondering if it's possible have 2 enterprise certificate authorities setup on 1 domain.
i have implemented enterprise root ca, using microsoft script, issue server certificates our ias servers. simple special purpose ca formed part of microsoft solution securing wireless lans peap. works , don't want touch it. need implement more general purpose pki solution - install enterprise root ca in our domain? have single forest single domain.
thanks help
martin
i have run number of clients have done accidently, can done.
however, having said that, should expand functionality of original ca include new set of techincal requirements or create master pki , roll in old functionality new infrastructure.
managing 2 sets of crls , 2 cas going increasing administrative difficulty. also, should have offline root each of these cas - managing multiple offline ca roots going increasing cost.
i work hard in short term save kinds of difficulty in long term.
Windows Server > Security
Comments
Post a Comment