Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 818
  • Last Modified:

Setting up Subordinate Enterprise CAs for redundancy

I have inherited a project from a admin that is no longer with our company.  That admin and setup an on-line Enterprise CA on a member server for issuing autoenrollment and to request internal certs.  I have been asked to setup subordinates to help offload requests and to serve as backups if the CA goes down for any reason.  In reading the MS documentation it appears all that is needed is to install CA and specify Enterprise Subordinate CA and request a cert from the parent.  Is there anything else that needs to be done on either the root or the subordinates?  Can the subordinate be on a member server?
0
swlundq
Asked:
swlundq
  • 3
  • 2
1 Solution
 
PakaCommented:
That' s all there is to setting up a Enterprise Subordinate CA.  The subordinate can be on a member server.  

Best practice is to setup Enterprise Subordinate CA(s) to issue the certs, then take the Enterprise Root offline to protect the root (most trusted cert in the domain).  Most orgs don't go to that extreme; however don't forget to backup your Enterprise Root CA and keep it in a safe place (either through system state or backing up the cert itself).
0
 
swlundqAuthor Commented:
Thanks, but what about certificate templates?  They don't seem to have replicated to the subordinate.  I did the install of the subordinate yesterday and it still just has the default templates.
0
 
PakaCommented:
That's correct, you'll have to install the templates on the subordinates too.  Here's a good webcast and PowerPoint on some of the details of Enterprise Subordinate implementations (Even though is covers an off-line root and on-line subordinate.)

http://support.microsoft.com/kb/896737
0
 
swlundqAuthor Commented:
That helped, but just to be sure as the webcast dealt with off-line CA.  As my root is on-line do I need to do the certutil -dspublish "CRT File" ROOTCA steps on the subordinate or do I just need to issue the templates on the subordinate?
0
 
swlundqAuthor Commented:
I just added the templates and it appears to be working.  Thanks for the information.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now