Re: Stand-alone vs Enterprise subordinate CA?



Inline

In article <#7vls#mYHHA.4232@xxxxxxxxxxxxxxxxxxxx>,
MarlonBrown@xxxxxxxxxxxxxxxxxxxxxxxxx says...
I am setting up a 2 tier PK infrastructure, Win2003 Ent.

Offlline root CA is already configured. On my offline root ca server. On AIA
I informed a \\publicserver\shared\myucert.crt - OK. I put the cert out of
the OffLineRootServer because I understand such server should remain shut
down for the most part.


I would personally never post an CA certificate to a UNC name (even
though supported). Consider changing to LDAP and HTTP locations. the
Best Practices whitepaper provides guidance on this
(www.microsoft.com/pki)

Next step on the Windows 2003 PKI checklist is:

"Install subordinate certification authorities, as required by your planned
certification hierarchy. These can be stand-alone certification authorities,
or if you are using Active Directory, enterprise certification
authorities...".

You would want an enterprise CA. To take full advantage of the CA
offering, ensure that you install on Windows Server 2003, Enterprise
Edition, not standard edition.


Since my "OnlineCAserver" is joined to AD, should I pick the "stand-alone
subordinate" or "enterprise subordinate certification authority".

Sorry if that is a stupid question.



Brian
.



Relevant Pages

  • Re: Key Recovery Agent in .NET CA
    ... I search on "version 2 templates" and this is the first hit in the search ... Windows .NET Enterprise Server and Windows .NET Datacenter Server ... Version 2 templates are only available as part of a certification authority ...
    (microsoft.public.win2000.security)
  • Stand-alone vs Enterprise subordinate CA?
    ... Offlline root CA is already configured. ... On my offline root ca server. ... "Install subordinate certification authorities, ...
    (microsoft.public.security)
  • ~~~~~ SUN JAVA ~~~~~
    ... ENTER HERE: ... sun java system application server password ... downloadable certification e-books on sun java ... java sun certified developer nederland ...
    (sci.math)
  • Re: [Media] Commentary: How About a Useful MCSE Certification?
    ... microsoft product of some kind) ... > uncertified to MCSE, and it opened my eyes to an awful truth: ... > Microsoft certification programs over the past 10 years knows that I'm ... > as many questions about NTBackup as are on the server test? ...
    (microsoft.public.cert.exam.mcse)
  • Re: Formal Training
    ... and then came the time for the server upgrade. ... SBS NG myself out of. ... > your head, maybe its reading a bit at a time here, on Google and in MS ... >> test I'd ever taken for any sort of certification. ...
    (microsoft.public.backoffice.smallbiz2000)

Loading