Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


Multiple domain Certificate Authority

Posted on 2009-02-16
Medium Priority
Last Modified: 2012-05-06
My job requires me to build a Certificate Authority Infrastructure for our project. It will be Microsoft Certificate Authority. This is a foreign infrastructure so it has 5 different domains. They are: asia, europe, south america, africa and north america. Each of these domain has its own domain name space. For example: us.xx.xx.xx.gov, eur.xx.xx.xx.gov.

Do I have to build 5 different Certificate Authority for these 5 domains? Or can I just build one insfrastructure for all 5 domains?

Question by:dongocdung
  • 2
LVL 22

Assisted Solution

Paka earned 1500 total points
ID: 23657783
Sounds like a fun project!  The answer is - it depends.  Are you running all these domains in the same forest or are they different forests?  Are you going to run your CA as an Enterprise Root CA or a Standalone CA?  What are you going to use your CA(s) for (ie PKI, SmartCard Logon, Web Authentication,etc)?

Author Comment

ID: 23659108
All of these domains are in the same forest.
The CA is running as an Enterprise Root CA
The CA is use for smartcard logon, machine cert and VPN.
LVL 22

Accepted Solution

Paka earned 1500 total points
ID: 23659169
You can get by with a single Enterprise Root CA.  However, best practice is to create a couple Enterprise Subordinates (for fault tolerance) to issue the certs and to take the Enterprise Root offline (for security purposes).

How big of an enterprise will you be serving?

Featured Post


Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
Screencast - Getting to Know the Pipeline

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question