Re: Stans-alone root CA or Enterprise root CA



Unless you are going to be using a stand alone offline root CA which would
be very unusual for a small domain you really want to an Enterprise CA in a
domain. If not too much of a problem you could uninstall CA services from
the server and reinstall it as Enterprise CA. Enterprise CA can make it much
easier to request and issue computer and possibly user certificates via
Group Policy particularly when the CA is installed on Windows 2003
Enterprise edition which lets you use version 2 templates. You might be able
to do what you want to issue the certificate needed for the WIFI as is but
down the road you may want to take more advantage of PKI in your domain and
then you will appreciate an enterprise CA.


"pestocat" <gel114@xxxxxxxxxxxxxxxxx> wrote in message
news:OIV2L1UzGHA.3748@xxxxxxxxxxxxxxxxxxxxxxx
I have a small domain that I want to setup EAP/PEAP for a WIFi wireless
switch environment and need to issue certificate to the switch. I have
already installed a Stand-alone root CA, but after reading Chapter 10 of
"The Ultimate Windows Server 2003 System Administrator's Guide", I get the
impression I should have installed Enterprise root CA. Is this correct.
What are the tradeoffs?
Thank you



.



Relevant Pages

  • Re: Certificate chain issue with Ent Sub Ca & stand alone Root CA
    ... certificate and I get a "Cannot verify certificate chain. ... revocation because the revocation server was offline. ... the root ca? ... Online>>> Online Enterprise Subordinate CA ...
    (microsoft.public.windows.server.security)
  • Re: How to determine Role on a installed CA?
    ... If you do you can be 100% sure you have Enterprise ... To see if it is subordinate or root, check your CA certificate... ...
    (microsoft.public.windows.server.networking)
  • Re: W2K3 3-tier CA Implementation
    ... No matter what environment you are in, install a standalone ROOT CA. ... based on the standalone subordinate CA. ... I agree with issuing CAs being enterprise CAs. ... You do not use a certificate tempalte for the ...
    (microsoft.public.security)
  • Re: Need advice for CA Model
    ... The root CA must be trusted on all the clients that will enroll to the ... certificates, each certificate must correspond to a user in AD with a UPN ... The enterprise CA automatically creates ... The second CA was a standalone ...
    (microsoft.public.win2000.security)
  • Re: W2K3 3-tier CA Implementation
    ... for a W2K3 Enterprise CA solution. ... How do you intend to change an online CA to an offline CA? ... *standalone* CAs for the root and policy tier. ... You do not use a certificate tempalte for the ...
    (microsoft.public.security)