EV Certificates and Multilayer Internal PKI


hi,

we have standalone offline root ca , domain joined issuing ca setup, both on server 2012 r2. have been asked ev certificates deployed internally , saw site below:

https://blogs.technet.microsoft.com/askds/2009/08/14/extended-validation-support-for-websites-using-internal-certificates/

at end of document talks adding root ca trusted root ca on domain , adding oid of certificate template created it. thing have not deployed our root ca way, using command - certutil -dspublish -f <certfilename> rootca.

would create duplicate certificates in clients trusted root container on each pc if add again? also, have not published intermediate certificate @ all, assume because domain joined automatically publishes out intermediate certification authorities container on each pc.  if add certificate global group policy , make oid changes? how affect existing users?

thanks lot reading.

it create duplicate object on clients, not cause problem @ all. in fact, when publish ad, clients wind 2 copies default. multiple copies not issue.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2