Re: Standalone/ Enterprise CA issue

From: Paul Adare (padare_at_newsguy.com)
Date: 10/18/05


Date: Tue, 18 Oct 2005 04:23:18 -0400

In article <F4DF253A-5E71-45FF-AFEB-A4954F1C711E@microsoft.com>, in the
microsoft.public.security news group, =?Utf-8?B?bGJjYmVu?=
<lbcben@discussions.microsoft.com> says...

> Hi,
>
> I need some answer to my simple question
>
> Crrently, my company running Standalone CA(Win2003) as Root, and running
> Subordinate Enterprise CA(Win2003), running on AD
>
> 2 Question here:
> 1. Any way to perform auto-renew and auto-enrollment with this structure
> with standalone as Root, while Subordinate with Enterprise CA?

Autorenew and autoenroll which certificates? End entity certificates
that are issued from the SubCA or the CA certificates themselves? If the
former then yes, as long as the clients are XP or above. If the latter,
no. Renewing and enrolling CA certificates is a manual operation.

>
> 2. If cannot perform auto-renew and auto-enrollment, beside reinstall
> everything, anyway to convert existing standlone CA(Root) to Enterprise CA
> (Root) within the server?

No.

-- 
Paul Adare
MVP - Windows - Virtual Machine
http://www.identit.ca/blogs/paul/
"The English language, complete with irony, satire, and sarcasm, has
survived for centuries without smileys. Only the new crop of modern 
computer geeks finds it impossible to detect a joke that is not clearly 
labeled as such."
Ray Shea


Relevant Pages

  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... we will need to have trust ... As far as standard versus enterprise, ... If the root CA is compromised your whole PKI ... > your certificates then it would make sense to use your own CA. ...
    (microsoft.public.windows.server.security)
  • Re: Public Key on Enterprise CA
    ... 2000 or Windows Server 2003 Enterprise CA. ... I see that Verisign will sell ... > digital certificates for about $15 per user. ... > savings by managing your own subordinate CA with Verisign as the root CA ...
    (microsoft.public.win2000.security)
  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... If the root CA is compromised your whole PKI is ... your certificates then it would make sense to use your own CA. ... > enterprise level certification authority. ... > and 1 or more subordinate CAs. ...
    (microsoft.public.windows.server.security)
  • Re: Need advice for CA Model
    ... > The root CA must be trusted on all the clients that will enroll to the ... > certificates, each certificate must correspond to a user in AD with a UPN ... The enterprise CA automatically creates ... The second CA was a standalone ...
    (microsoft.public.win2000.security)
  • Transition from a single enterprise CA to a tiered CA
    ... After reading about best practices, ... subordinate enterprise CAs. ... (For the number of certificates we use, ... once the new subordinate enterprise CA is up and running, ...
    (microsoft.public.windows.server.security)