Scrambles Posted August 7, 2018 Posted August 7, 2018 Hey Folks, Just want to pick your collective brains for a moment. I am going down the route of setting up a new PKI for the school with a look at enabling 802.1x for our PC's to stop students plugging on their own devices and getting onto the internal network. I plan to install an Offline RootCA and a subordinate CA. My question would be - where do you install the subordinate CA ? Does it go onto the domain controller or do you put it on it's own server ? Thanks in advance.
ITGuyWestMidlands Posted August 7, 2018 Posted August 7, 2018 Don't put it on a DC as the DC cannot be demoted in the future whilst ADCS is installed 1
AlanD Posted August 7, 2018 Posted August 7, 2018 It wouldn't be fool proof.....but you could turn all your DHCP addresses for exisiting devices into reserved addresses...and allocated new devices to a different subnet - or different gateway (or vlan)…..so someone plugging in a laptop or something is not going to work.... (Of course...if they realise what is going on they can work around this....but my guess is that it would stop most)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now