Re: PKI Certificate Server Install in AD Empty Root Domain

From: FastEddie (fasteddie_at_therockwells.net.no.spam)
Date: 07/21/05


Date: Thu, 21 Jul 2005 15:11:28 -0500

Questions inline:

"Brian Komar" <MVPbkomar@nospam.identit.ca> wrote in message
news:MPG.1d49905ceafd6bb39896c3@msnews.microsoft.com...
> Answers inline:
>
>
>
> In article <eVKgergjFHA.1232@TK2MSFTNGP15.phx.gbl>,
> fasteddie@therockwells.net.no.spam says...
>> Platform: Windows 2003 AD with an empty root
>>
>> We are installing an Enterprise CA in our Active Directory 2003 Forest.
>> All
>> our resources, users, and computers and effective GP settings are in a
>> domain under the empty forest root domain.
>>
>> My questions:
>>
>> If I install the CA in the forest root, will the certificates and auto
>> issuing of certificates work correctly in the other domains within the
>> forest or should I install the Enterprise CA in the domain that houses
>> all
>> the resources, machines and users?
>
> It really does not matter which domain you install the certificates in.
> Whichever domain you choose, you will have to do some additional work to
> issue certificates to other domains in the forest.
> 1) Certificate templates. The default permissions will only include
> groups in the forest root domain. You must modify permissions for other
> domains to assign Read and Enroll perms (possibily autoenroll).
> 2) Publication to AD to the userCertificate attribute. An enterprise CA
> by default can only publish certificates to user objects in the same
> domain. Follow the instructions in Q281271 "Windows 2000 CA Config. to
> Publish Certs in AD of Trusted Domain" to assign the correct perms to
> the Cert Publishers group to the other domains in the forest.
>
>>
>> Also, can I use this CA to issue certs in another Forest?
>
> No. A CA can only issue certs to users in the same forest. You can in
> some cases, if the subject is provided in the request, but what you may
> want to look at is a root that is not specific to either forest, and
> then subordinate CAs in each forest.

So you are saying I could have a Ent CA in my forest root (forest A, Domain
A) and a subordinate in my member domain (Forest A, Domain B) to auto issue
certs for machines and accounts?

Then also have a Subordinate CA in Forest B but not in the root domain, in a
sub domain Forest B...?

Both subordinates can auto issue certs for machines and accounts?

>>
>> thanks,
>>
>> Fast Eddie
>>
>>
>>
>
> --
> ==
> Brian Komar
> MVP - Windows - Security
> http://www.identit.ca/blogs/brian



Relevant Pages

  • Re: Global Catalog Failure
    ... installed, you can install them from your server install disk. ... You should NOT make every DC a GC in a LARGE forest, ... You should have a MINIMUM of two GCs per site for fault tolerance. ... But with small forests you can just make all DCs GCs and get ...
    (microsoft.public.win2000.active_directory)
  • Re: Rename / Reorganise Domain
    ... So the NetBIOS name is www. ... The AD is in mixed mode but no NT 4.0 servers installed. ... Forest root of domain.com ... If you want to rename it, the best thing to do is install a fresh 2003 ...
    (microsoft.public.win2000.active_directory)
  • Re: Q on Installing 2nd Exchange Server In Trusted Domain
    ... >was installed it was created under the forest created with the first domain). ... >ForestPrep, DomainPrep, Setup) as setting up the first Exchange server in NJ? ... > When the French Exchange install runs, should it by default find the ... >Exchange Organization created in NJ and be able to install as part of the ...
    (microsoft.public.exchange.setup)
  • Re: DNS-Urgent-Help -Please
    ... > We are Planing to Have One Forest, ... > i am going to install KTC.COM as the Forest Root Domain, ... > Install DNS ... > server on one Machine and configure one Forward Zone with name ...
    (microsoft.public.win2000.active_directory)
  • Re: DNS-Urgent-Help
    ... > We are Planing to Have One Forest, ... > i am going to install KTC.COM as the Forest Root Domain, ... > Install DNS ... > server on one Machine and configure one Forward Zone with name ...
    (microsoft.public.win2000.dns)