Jump to content

Recommended Posts

Posted

Hey Folks,

 

Just want to pick your collective brains for a moment.

I am going down the route of setting up a new PKI for the school with a look at enabling 802.1x for our PC's to stop students plugging on their own devices and getting onto the internal network.

 

I plan to install an Offline RootCA and a subordinate CA. My question would be - where do you install the subordinate CA ? Does it go onto the domain controller or do you put it on it's own server ?

 

Thanks in advance.

Posted

It wouldn't be fool proof.....but you could turn all your DHCP addresses for exisiting devices into reserved addresses...and allocated new devices to a different subnet - or different gateway (or vlan)…..so someone plugging in a laptop or something is not going to work....

 

(Of course...if they realise what is going on they can work around this....but my guess is that it would stop most)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...