Re: Issuing CA - Common Name?



Hi
the reason why it must have a different common name is because being an
enterprise CA it publishes certain information to Active Directory. If 2
enterprise CAs had the same common name then there would be 2 machines trying
to publish the same data.
The easiest way to find the data I am talking about it to start 'Active
Directory Sites and Services'
Click to high-light Active Directory Sites and Services[FQDN of domain
controller]
Click View > Show Services Node
Now expand Services
Expand 'Public Key Services'
Look in the AIA, CDP, Enrollment Services folders for Enterprise CA info.

"BillL" wrote:

On Jun 23, 5:11 pm, Paul Adare <pkad...@xxxxxxxxx> wrote:
On Mon, 23 Jun 2008 13:44:42 -0700 (PDT), BillL wrote:
Our MS PKI environment currently includes 1 offline root CA and 1
online enterprise issuing CA. We want to add a 2nd enterprise issuing
CA for redundancy. I believe that this 2nd issuing CA should have a
different Common Name than the 1st issuing CA. It's not clear from
the documentation that I have looked at. Is this a correct
assumption?

It _must_ have a different common name.

--
Paul Adarehttp://www.identit.ca
Programmers do it bit by bit.

Thanks Paul.

.



Relevant Pages

  • Re: PKI Question
    ... Because an Enterprise CA is integrated with Active Directory which requires ... stand-alone root CA. ... An enterprise root requires access to the Active ... You should not install an enterprise root on an offline domain ...
    (microsoft.public.security)
  • Re: active directory security
    ... >When I make a security change in active directory for a built in group ... >i.e (administrators,domain admins, and enterprise admins)the change ...
    (comp.os.ms-windows.nt.admin.security)
  • autologon vista
    ... Enterprise or Ultimate in an Active Directory domain. ... Autologon account would be a local account on the system ... Is that solution can be managed through group policy for Vista Enterprise ...
    (microsoft.public.windows.group_policy)
  • Re: CAn CRL and GPO
    ... You may want to consider an Enterprise CA for an AD domain as it has several ... advantages and you could still use your stand alone root CA with the ... Is there a way to force Outlook to consult the CRL, ... Can I publish revocated certificates in my Active Directory or in share ...
    (microsoft.public.windows.server.security)
  • Re: Multiple-purpose client certs, how?
    ... Doesn't Enterprise CA require Active Directory? ... Active Directory in the past and rather do so in the future. ... >> given a choice of either a Web Browser Certificate or a Email Protection ... >> for both Client Authentication and Secure Email purposes? ...
    (microsoft.public.win2000.security)