Jump to content

Recommended Posts

Posted

I am planning to move an Enterprise Root CA which is currently sitting on a Server 2008 box, which is also a DC.

This server is named WIN-DC01

 

I would like to move the CA to one of my other DCs which are named

DC01 & DC02

 

The certs which are currently issued are computer certs for RADIUS.

 

I need to make the process happen without effecting clients using 802.1x

 

Any advice or recommended steps would be much appreciated.

 

Thanks in advance

Posted (edited)

My first thought on this is not to use a DC for your Root CA, I would try to keep the root CA offline and only power it up when required.

 

Some useful info here https://social.technet.microsoft.com/wiki/contents/articles/2900.offline-root-certification-authority-ca.aspx

and here https://technet.microsoft.com/en-us/library/cc700804.aspx

 

WBSessionNotes.GIFWBSession.GIF

 

Above are some screen grabs of a chalk and talk with MS I had recently.

Edited by HPlum78
Posted

Like @HPlum78 said you really shouldn't setup a CA on a DC.

 

Ideally you would have a root CA in its own VM (kept offline and not a member of the domain) and a subordinate CA in a separate VM that is used to issue certificates. See the links below for more details.

 

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...