Advice on Enterprise certificate setup

hi guys,

i have 30 domain controllers, with two of them splitting fsmo roles as my main DC's.
I am about to install certificate services, but i wanted to get some opinions on what is the best setup for this architecture. I know there is root and ca root etc, is it best to a have a seperate certificate on each dc or have it all connected to the main dc? the plan is to use it for radius for networking equipment server etc, as well as wireless authentication
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Kent DyerIT Security Analyst SeniorCommented:
Just like you have redundancy in DCs in your domain, you should have redundancy in your ca.  If you have only one ca and it was to go offline, you need a backup.  If you don't people could have trouble authenticating to your domain and possible host of other issues.


Hi, you should consider what design you should go for (how many tier, offline Enterprise root CA, how many issuing CAs, etc).  

You should also avoid placing the CA server role on a DC, because that's making the ADCS role dependant on the ADDS role and also because it makes it difficult to separate the CA manager role from the Domain Administrator role. If you place the CA on a DC, you can't demote a DC without moving the CA to another server.

Here are some pros/cons for a 1 and 2 tier Enterprise CA:

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.