Enterprise Root CA


 

hi

 

i wondering if it's possible have 2 enterprise certificate authorities setup on 1 domain.

i have implemented enterprise root ca, using microsoft script, issue server certificates our ias servers. simple special purpose ca formed part of microsoft solution securing wireless lans peap. works , don't want touch it. need implement more general purpose pki solution - install enterprise root ca in our domain? have single forest single domain.

 

thanks help

 

martin

i have run number of clients have done accidently, can done.

 

however, having said that, should expand functionality of original ca include new set of techincal requirements or create master pki , roll in old functionality new infrastructure.

 

managing 2 sets of crls , 2 cas going increasing administrative difficulty.  also, should have offline root each of these cas - managing multiple offline ca roots going increasing cost.

 

i work hard in short term save kinds of difficulty in long term.

 



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2