PKI in multi sites/domains environment


First, sorry for my poor english, French NG doesn't answer for my
I explain my need.
I have an AD forest which looks like this :
A root domain (technical domain, no user account) called ROOT.LOCAL.
I have two domain trees ASIA.LOCAL and AMERICAS.LOCAL.
There are 4 sub-domains called JAPAN.ASIA.LOCAL, CHINA.ASIA.LOCAL (for
AD site configuration match name locations.
I want to implemant CA hierarchy like that :

One offline ROOT CA, 2 offline policy CA (one for each location, ASIA
& AMERICAS) and one issuing CA for each domain tree.

1. I want to know how can I be sure that users in ASIA tree will never
ask certificate on CA of AMERICAS tree ? Is it possible ? In technet,
it is specified that CA services (as a forest service) don't use site

I have several questions too.
(I numbered for easy answers.)

2. Is there one CRL distribution point for a CA or for a CA
hierarchy ?
3. When a client have to check certificate chain, does it established
a network connection with each CA ? Just one ? Any ?
4. Whan I add a CRL distribution point, I have to renew older
certificates ? If I don't, does older certificates still valid ?

I have some difficulties to identify what are the logical and physical
componments in PKI...

Thanks for your help.



Relevant Pages

  • Re: PKI in multi sites/domains environment
    ... I have two domain trees ASIA.LOCAL and AMERICAS.LOCAL. ... AMERICAS tree). ... & AMERICAS) and one issuing CA for each domain tree. ... The other way is to create custom certificate templates that limit enrollment to a subset of the users, and only publish the America servers at the Americas CAs. ...
  • Re: Newbie questions about pruning privet hedge
    ... I make decisions based on tree biology when possible regarding forest health ... I understand that you have a background in wood products, ...
  • logging comment
    ... environmental disgrace; it had a huge, huge economic impact,". ... Beware of so-called forest experts who do not understand of tree ... biology. ...
  • Re: AD Forest Split Procedure
    ... Exchange data was exported, Exchange ... Two business originally one owner, one domain, one forest. ... cleanup; about a two or three days each. ... one DC from the other tree and of course DC's ...
  • Re: Landscaping Shrubs: Spruce Up Your Yard
    ... What's important is that tree biology is considered when making decisions on ... the studies drifted toward wood ... In 1907 the lab was discontinued and the Forest Products ...