Jump to content

Recommended Posts

Posted

Good morning everyone!

 

We currently run Active Directory Certificate Services across our domain. We have a stand-alone root certificate authority and a single intermediate certificate authority. We use Group Policy to deploy the root and intermediate certificates to workstations and auto-enrol the workstations using the “Computer” template. We are looking to expand upon this setup by adding a second intermediate certificate authority from the root that at the least can serve a separate site and at best can provide some redundancy for certification requirements. However, I am unclear on some of the mechanics of this and relevant documentation appears sparse.

 

A few questions:

  1. I don’t see anywhere in Group Policy where I am able to actually specify what intermediate CA to enrol with. I am assuming that this is dictated simply by which intermediate certificates are published via Group Policy?
  2. If this is correct, if we wanted to have workstations enrol with multiple intermediate CAs would it just be case of publishing each of them via GP?
  3. Is there any way to influence which of the two intermediate CAs a workstation will enrol with?
  4. Is it possible to set up cross-certification, where certificates from one intermediate are trusted by the other?
  5. Is there any way to have a workstation enrol with more than one intermediate CA?

 

Thanks in advance for any help with this enquiry!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...