Setting up Subordinate Enterprise CAs for redundancy

Posted on 2009-02-23
Last Modified: 2012-05-06
I have inherited a project from a admin that is no longer with our company.  That admin and setup an on-line Enterprise CA on a member server for issuing autoenrollment and to request internal certs.  I have been asked to setup subordinates to help offload requests and to serve as backups if the CA goes down for any reason.  In reading the MS documentation it appears all that is needed is to install CA and specify Enterprise Subordinate CA and request a cert from the parent.  Is there anything else that needs to be done on either the root or the subordinates?  Can the subordinate be on a member server?
Question by:swlundq
    LVL 22

    Expert Comment

    That' s all there is to setting up a Enterprise Subordinate CA.  The subordinate can be on a member server.  

    Best practice is to setup Enterprise Subordinate CA(s) to issue the certs, then take the Enterprise Root offline to protect the root (most trusted cert in the domain).  Most orgs don't go to that extreme; however don't forget to backup your Enterprise Root CA and keep it in a safe place (either through system state or backing up the cert itself).

    Author Comment

    Thanks, but what about certificate templates?  They don't seem to have replicated to the subordinate.  I did the install of the subordinate yesterday and it still just has the default templates.
    LVL 22

    Accepted Solution

    That's correct, you'll have to install the templates on the subordinates too.  Here's a good webcast and PowerPoint on some of the details of Enterprise Subordinate implementations (Even though is covers an off-line root and on-line subordinate.)

    Author Comment

    That helped, but just to be sure as the webcast dealt with off-line CA.  As my root is on-line do I need to do the certutil -dspublish "CRT File" ROOTCA steps on the subordinate or do I just need to issue the templates on the subordinate?

    Author Comment

    I just added the templates and it appears to be working.  Thanks for the information.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Join & Write a Comment

    The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
    This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

    731 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now