EV Certificates and Multilayer Internal PKI
hi,
we have standalone offline root ca , domain joined issuing ca setup, both on server 2012 r2. have been asked ev certificates deployed internally , saw site below:
https://blogs.technet.microsoft.com/askds/2009/08/14/extended-validation-support-for-websites-using-internal-certificates/
at end of document talks adding root ca trusted root ca on domain , adding oid of certificate template created it. thing have not deployed our root ca way, using command - certutil -dspublish -f <certfilename> rootca.
would create duplicate certificates in clients trusted root container on each pc if add again? also, have not published intermediate certificate @ all, assume because domain joined automatically publishes out intermediate certification authorities container on each pc. if add certificate global group policy , make oid changes? how affect existing users?
thanks lot reading.
mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com
Windows Server > Security
Comments
Post a Comment