Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Standalone v's Enterprise Root CA's

Reply
Thread Tools Display Modes

Standalone v's Enterprise Root CA's

 
 
Cosmo
Guest
Posts: n/a

 
      04-05-2010
I'm new to W2K8 CA's and was wondering if someone could please answer my
below questions:

1) What are the pro's and con's between a Standalone and an Enterprise Root
CA?

2) Does a Root CA always has to been online for NAP with IPsec to work?

3) Does a Root CA have to be online of a Subordinate CA to automatic enrol a
certificate to a client?

4) For HA reasons, can you MSCS cluster Subordinate CA's?

Cheers,
Cosmo
 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      04-06-2010
Hello Cosmo,

I am not the AD CS expert but hopefully this helps to start:

1. See here for details about, applies also for Windows server 2008:
http://technet.microsoft.com/en-us/l...89(WS.10).aspx

http://technet.microsoft.com/en-us/l...95(WS.10).aspx

2. According to this article you should use your own NAP CA as standalone
or a subordinate CA:
http://technet.microsoft.com/en-us/l...44(WS.10).aspx

Also check this one:
http://www.microsoft.com/downloads/d...displaylang=en

3. No, the subordinate can work alone and many organizations minimize the
exposure of their root CA by keeping it offline except when it is needed
to process a request for a subordinate CA certificate.:

4. See here about clustering AD CS within Windows server 2008:
http://technet.microsoft.com/en-us/l...17(WS.10).aspx

See here about all resources:
http://technet.microsoft.com/en-us/l.../cc534992.aspx

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I'm new to W2K8 CA's and was wondering if someone could please answer
> my below questions:
>
> 1) What are the pro's and con's between a Standalone and an Enterprise
> Root CA?
>
> 2) Does a Root CA always has to been online for NAP with IPsec to
> work?
>
> 3) Does a Root CA have to be online of a Subordinate CA to automatic
> enrol a certificate to a client?
>
> 4) For HA reasons, can you MSCS cluster Subordinate CA's?
>
> Cheers,
> Cosm



 
Reply With Quote
 
Cosmo
Guest
Posts: n/a

 
      04-06-2010
Meinolf,

Thanks for your excellent response. I'll have a read of the URL's and see
how I go.

Cheers,
Cosmo :-)
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Place holder root domain advantage Randy Jackson Active Directory 16 03-16-2010 11:29 AM
RE: renew root ca to extend validity period Stardust Server Security 0 01-29-2010 08:32 PM
In case you find this blog and have read through... Rob Ness File Systems 0 01-27-2010 02:24 PM
2nd Domain in a 2 domain forest cannot be contacted David Alge DNS Server 30 01-21-2010 05:26 AM
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 01:00 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59