Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?



Hi,

we are planning to deploy a certificate hierarchy.

First, we will have a Root CA (standalone Offline) and a subordinate CA (enterprise online integrated to AD).

My question is which certificate should I have to deploy to my computer Trusted Root Certification Authorities Store ? The Root CA or the Subordinate CA ?

I have read in Microsoft website that it should be the Root CA certificate (and not the Subordinate CA) but I dont understand why !

Indeed, imagine that in the future we decide to install a new subordinate Enterprise CA (child of the Root CA, so a brother of the first subordinate CA) for a new acquired company;

If we have installed the Root CA in our domain member computers, then they will trust every certificate delivered by the new subordinate Enterprise CA, am I right ?
This is not very nice as the new sub enterprise CA is not defined to trust computers for the "whole company" but just for the newly acquired company.

Please could you tell me what do you think about that ?

Thanks

--
Pascal


.



Relevant Pages

  • Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
    ... If a subordinate chains to a trusted root CA, ... Best bet is for your to read the certificate revocation and status checking whitepaper that describes how certificates are verified. ...
    (microsoft.public.windows.server.security)
  • Re: Certificate chain issue with Ent Sub Ca & stand alone Root CA
    ... certificate and I get a "Cannot verify certificate chain. ... revocation because the revocation server was offline. ... the root ca? ... Online>>> Online Enterprise Subordinate CA ...
    (microsoft.public.windows.server.security)
  • Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
    ... "Only root CA certificates must be trusted and registered on client computers. ... So I am not understanding that I have to trust the subordinate CA as you said. ... My question is which certificate should I have to deploy to my computer Trusted Root Certification Authorities Store? ... If we have installed the Root CA in our domain member computers, then they will trust every certificate delivered by the new subordinate Enterprise CA, am I right? ...
    (microsoft.public.windows.server.security)
  • Re: Subordinate CA
    ... CA servers Enterprise CA setup? ... How was certificate issued to OWA? ... > My company has an Enterprise Root CA in Colorado and many Subordinate CA ...
    (microsoft.public.win2000.security)
  • Re: How to determine Role on a installed CA?
    ... If you do you can be 100% sure you have Enterprise ... To see if it is subordinate or root, check your CA certificate... ...
    (microsoft.public.windows.server.networking)