Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?



This is basic PKI. Trust is established at the root.
If the CA is a subordinate of a trusted root, you trust the CA.
I would recommend reading Polk and Housley
Brian

"Pascal" <pascal_t@xxxxxxxxxxxxxxxxxx> wrote in message news:mn.d2a87d837c712979.70874@xxxxxxxxxxxxxxxxxxxxx
Hi,

we are planning to deploy a certificate hierarchy.

First, we will have a Root CA (standalone Offline) and a subordinate CA (enterprise online integrated to AD).

My question is which certificate should I have to deploy to my computer Trusted Root Certification Authorities Store ? The Root CA or the Subordinate CA ?

I have read in Microsoft website that it should be the Root CA certificate (and not the Subordinate CA) but I dont understand why !

Indeed, imagine that in the future we decide to install a new subordinate Enterprise CA (child of the Root CA, so a brother of the first subordinate CA) for a new acquired company;

If we have installed the Root CA in our domain member computers, then they will trust every certificate delivered by the new subordinate Enterprise CA, am I right ?
This is not very nice as the new sub enterprise CA is not defined to trust computers for the "whole company" but just for the newly acquired company.

Please could you tell me what do you think about that ?

Thanks

--
Pascal



.



Relevant Pages

  • Re: Which certificate do I have to deploy ? Root CA or Subordinate CA certificate ?
    ... I have understood too that if I install the Root CA cert, I will trust ... every subordinate CA even if I dont have their certificates installed. ... But my question is "why does Microsoft recommend to install the root CA ...
    (microsoft.public.windows.server.security)
  • Re: How to determine Role on a installed CA?
    ... If you do you can be 100% sure you have Enterprise ... To see if it is subordinate or root, check your CA certificate... ...
    (microsoft.public.windows.server.networking)
  • Re: W2K3 3-tier CA Implementation
    ... No matter what environment you are in, install a standalone ROOT CA. ... based on the standalone subordinate CA. ... I agree with issuing CAs being enterprise CAs. ... You do not use a certificate tempalte for the ...
    (microsoft.public.security)
  • Warning message about valid certificates
    ... I installed an Enterprise Root CA for my 50-user win2000 ... Certificate Revocation List needed to verify the signing ... In the Edit Trust ... Why do I see this warning message? ...
    (microsoft.public.win2000.security)
  • Re: CA Q
    ... I'm gonna start a new Root CA company. ... that I've done so far is issue a certificate to my IIS webserver. ... that possesses that the private key is reasonably the party that was issued the key and that the keys can used used for the attempted operation. ... This is where certification authorities come into play - they provide the trust structure. ...
    (microsoft.public.cert.exam.mcse)

Quantcast