Transition from a single enterprise CA to a tiered CA



We currently have a single Enterprise Certificate Authority installed on a
domain controller. After reading about best practices, I gather that this
is not really the right way to do it. (Plus I do not like being stuck with
this DC, if we needed to rebuild or remove it.)

I would like to set up an offline standalone root along with one or two
subordinate enterprise CAs. (For the number of certificates we use, I don't
think I need a 3-tier configuration.)

I don't see re-issuing the current certificates by hand to be a problem, but
once the new subordinate enterprise CA is up and running, how can I prevent
new auto-enrolled certificates from using the old CA before I've finished
moving everything? I'm not sure how long decommissioning the old one will
take, and if there is a way to be sure new certificates use the server, that
would help in the transition.


.



Relevant Pages

  • Re: Standalone/ Enterprise CA issue
    ... > Subordinate Enterprise CA, running on AD ... > with standalone as Root, while Subordinate with Enterprise CA? ... Autorenew and autoenroll which certificates? ...
    (microsoft.public.security)
  • Re: 2003/R2 certificate server questions
    ... running OPenSSL to service requests from Linux/samba ... certificates, but I also want to be able to issue random certificates ... Make sure you are running on Enterprise Edition, ... Automatic certs, Key archival and recovery, customizable ...
    (microsoft.public.windows.server.security)
  • Re: Enterprise Subordinate CA signed by third party Commercial CA like Verisign/Thawte/etc
    ... we will need to have trust ... As far as standard versus enterprise, ... If the root CA is compromised your whole PKI ... > your certificates then it would make sense to use your own CA. ...
    (microsoft.public.windows.server.security)
  • Re: client user certificates
    ... in certificates using Windows Server 2003 Enterprise Edition Enterprise CAs ... but it would be nice if there was a way to autoenroll the user. ... We have a Windows Server 2003 domain environment with a Enterprise ...
    (microsoft.public.windows.server.active_directory)
  • RE: CA Client Certificates only expire in one years time
    ... If this was installed as an Enterprise CA this is normal. ... which in v1 templates cannot be modified. ... "For certificates that are issued by Enterprise CAs, the validity period is ...
    (microsoft.public.windows.server.general)