cross forest certificate enrollment


we have 2 domains xyz.com , abc.com both have different ca

xyz.com has 2012r2 server

abc.com has 2003 server

so can create trust between 2 domains

i had gone through tech article (https://technet.microsoft.com/en-us/library/ff955845(v=ws.10).aspx)providing steps required deployment have seen issues steps provided.

additionally kind of rights required run commands certutil -config<computer-name>\<root-ca-name> -ca.cert<root certification authority.cer.cer> domain admin

and can commands run on an issuing ca or every command has run on root ca

regards

sharad pandey




that command can run creating copy of root ca certificate. can run anywhere in domain.

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. connect mark @ http://www.pkisolutions.com



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL