PKI Certificate Server Install in AD Empty Root Domain

From: FastEddie (fasteddie_at_therockwells.net.no.spam)
Date: 07/21/05


Date: Thu, 21 Jul 2005 10:42:56 -0500

Platform: Windows 2003 AD with an empty root

We are installing an Enterprise CA in our Active Directory 2003 Forest. All
our resources, users, and computers and effective GP settings are in a
domain under the empty forest root domain.

My questions:

If I install the CA in the forest root, will the certificates and auto
issuing of certificates work correctly in the other domains within the
forest or should I install the Enterprise CA in the domain that houses all
the resources, machines and users?

Also, can I use this CA to issue certs in another Forest?

thanks,

Fast Eddie



Relevant Pages

  • Re: Active Directory - security boundaries
    ... It doesn't actually make sense that the forest is the ONLY ... administrators in the internal domain (which is the forest root) will ... wouldn't be able to grant themselves access to resources in the other ... administrators of the standard domain can't grant themselves access to ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Controller/Global Catalog Planning
    ... > DC in Root. ... > for DCs, in the context of user logons at least. ... A GC of the forest should ... Were you to have sibling domains with resources ...
    (microsoft.public.windows.server.active_directory)
  • Enterprise Root Cas x 2?
    ... I have a AD Forest with two disjointed AD Domians being ... Enterprise Root CA ... Stand Alone Root CA ... As by normal train's of thought I'd install the Root ...
    (microsoft.public.win2000.security)
  • Re: Active Directory - security boundaries
    ... and hopefully from no one else the theory behind why the forest is the security boundary and what the holes are inside of a forest. ... > administrators in the internal domain will ... Obviously escalating a DA or Administrator or server operator in the root domain to EA is child's play, but the others are nearly as trivial. ... > wouldn't be able to grant themselves access to resources in the other ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory movements
    ... prod.local (root) all FSMO roles can't go over syst.local? ... >> In syst.local, the RID, PDC Emu, and IM roles resides ... >> I need move all servers, DC, resources, accounts .. ... How can i delete the root forest domain? ...
    (microsoft.public.win2000.active_directory)

Loading