?
Solved

Creating an Enterprise Sub CA

Posted on 2012-04-05
1
Medium Priority
?
318 Views
Last Modified: 2012-04-12
I created an offline root CA and now plan on creating a Sub CA to issue certificates to users and computers. I am in a 2003 and 2008 Active Directory domain. I would like to install IIS on the Sub CA so users can request certificates through web enrollment.

That question I have is, can I create an Enterprise Sub CA on a member server or does it have to be created on a DC?
0
Comment
Question by:AGenMIS
1 Comment
 
LVL 8

Accepted Solution

by:
Shmoid earned 2000 total points
ID: 37814437
Yes you can install the subCA on a member server. In fact, that is preferable. It is not best practice to install the CA role on a DC.
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question