Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > PKI branch office design

Reply
Thread Tools Display Modes

PKI branch office design

 
 
Jeff Vandervoort
Guest
Posts: n/a

 
      12-18-2009
WS2003 Functional-Level domain with 5 AD sites, each with a WS2003
DC/File/Print server. Sites are fully connected by RRAS L2TP/IPSec VPN.
Existing PKI is Enterprise Root CA at main office, currently on WS2003 R2
SP2 SE, with an Enterprise Sub CA at each branch office.

The expectation was that if a cert expired on an RRAS server leaving the VPN
link down, the RRAS box could renew its cert from a CA on its LAN. But what
has actually happened in real life, when the VPN link is down for any
reason, the CA service on the local DC won't even start, much less issue a
cert, because the CA can't check the CRL to see if its own Sub CA cert is
valid.

Enterprise CRL's are automatically published to AD, right? Each site has a
DC, and (not letting best practices get in our way, here) the CA is
installed on the DC, so AD availability should not be a problem.

Evidently there's a gap in this design somewhere...what do I need to do to
make sure each site has a CA available when the VPN link is down? Or is that
simply not possible?

Thanks!

--
Jeff Vandervoort
JRVsystems
http://www.jrvsystems.com

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 01:00 PM
Can't Install Office Service Pack 3 JamesJ Windows Update 15 12-04-2009 01:45 AM
6 updates failed - all with error code 0x80070643 NPJ Windows Update 4 11-23-2009 03:02 PM
Branch Office minime Windows Small Business Server 4 10-24-2009 08:42 PM
Windows & Office For Consumers Windows Vista General Discussion 17 03-17-2006 12:26 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59