Re: how many CA's (cross posted...)



Thanks Mario, you help was very useful.

Marco

"MarioC" wrote:




"Marco Tonoli" <MarcoTonoli@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:24BDF016-A293-4019-88CA-2E5AE8D055CD@xxxxxxxxxxxxxxxx
ok, so i issue a certificate from central, then crl and aia will found
locally trough the local DC because i correctly set "site and service"
applet. correct ?


Correct.

Perfect.

If there is a problem on the line to-from branch office... wht typi of
result i can have ? I thnk only problem if i need to rennovate a certificate,
so think is better to issue certificate with duration long, something like 30
gg and hope 30th day line is ok. Correct ?


If the line to your branch office goes down nobody could issue or renew new certificates. Since CRL and AIA information is stored in your AD applications including smart card logon are not affected.

I would suggest to set the certificate life time to about 1 year. You can set the renewal interval to about 6-8 weeks before expiration. So 6-8 weeks before the user's certificate is going to expire Windows XP can auto-renew the smartcard logon certificate. A "balloon tip" will pop up which informs the user that his certificate has to be renewed. The user only has to provide the PIN code to access the smart card.

Mario


Thanks

Marco


"MarioC" wrote:

Hi there,

Since the CA is only used when issueing certificates it would not make any
sense to install a second one in the branch office. All required information
(CRL, AIA) can be found redundant in AD.

Installing ca CA on a DC is supported. Best practice would be to install the
CA on a dedicated (virtual?) secure machine.

Mario




"Marco Tonoli" <MarcoTonoli@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AB81E25F-7CE9-4692-AB3E-AE9F7F0F1554@xxxxxxxxxxxxxxxx
Hi all, i have a question:

i have a PKI infrastructure, with a offline root, an enterprise CA and a
domain controller. We use PKI for smart card, email signing and what
future
time will offer...
Now we start a branch office with many user so i make a new domain
controller (for same central domain) in the branch office for
autentication
speed and geographics redundance. The lan's have non egual ip addressment
but
one see each other. I'll correctly set "site and service" applet so pc
remote
will use remote DC.
My question is... i need also a second CA in the branch office ? if not i
can have speed problem ? (i don't kon how fast is connection, specifically
during working hour).

And, if i need a second CA, can install on DC ? (i think have not CPU
power
problem and no security access problem) and there same particolar
procedure
to avoid strange situation like pc autentication or PKI process on erratic
CA
and DC ?

Thanks all in advance (and excuse my english.... writing from italy.)




.



Relevant Pages

  • Re: how many CAs (cross posted...)
    ... I thnk only problem if i need to rennovate a certificate, ... sense to install a second one in the branch office. ... Now we start a branch office with many user so i make a new domain ... I'll correctly set "site and service" applet so pc ...
    (microsoft.public.windows.server.security)
  • Re: how many CAs (cross posted...)
    ... I thnk only problem if i need to rennovate a certificate, ... If the line to your branch office goes down nobody could issue or renew new certificates. ... sense to install a second one in the branch office. ... I'll correctly set "site and service" applet so pc ...
    (microsoft.public.windows.server.security)
  • Re: how many CAs (cross posted...)
    ... sense to install a second one in the branch office. ... We use PKI for smart card, ... Now we start a branch office with many user so i make a new domain ... will use remote DC. ...
    (microsoft.public.windows.server.security)
  • Re: migration from Exch5.5 to Exch2003
    ... I plan to install AD (additional DC for ... In domain1 is exchange 5.5 which I plan to migrate ... on newly installed exchange 2003 added to domain2 located in branch office. ...
    (microsoft.public.exchange.admin)
  • Re: AD Structure
    ... wan links etc... ... install the server as a member first, then use dcpromo to make it a DC. ... If you don't want to do the initial replication over your wan, ... What kind of AD do I have to install on this branch office? ...
    (microsoft.public.win2000.active_directory)