Solved

How do I configure a Windows 2008 R2 Subordinate Certificate Server ?

Posted on 2014-09-17
5
259 Views
Last Modified: 2014-09-19
Hi everyone,

I am in the process of implementing a PKI environment. I have configured and created a CA root server.  I need this to be a 3 tier PKI infrastructure.  How do I create a subordinate server ? Do I export the root CA certificate and import it in to the subordinate server ?  I have read many articles but its just confusing...information overload.
0
Comment
Question by:CaussyR
  • 2
  • 2
5 Comments
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 40330161
that is correct you also have to create and enable a certificate request from the subordinate CA to the root ca and authorize the request and from the root ca export the certificate.  also you should create a group policy that adds the root certificate to the trusted root certificate store on all of the machines.

you can now shutdown the root certificate server.  the root ca should not be domain joined. preferably in a virtual machine.
0
 

Author Comment

by:CaussyR
ID: 40331363
Thanks David.

I have been looking for step-by-step instructions to build an offline intermediate server but can not find anything.  Please, could you let me know how to build an offline intermediate server ?

I have seen some documentation but this discusses running the certutil command line etc - is this required to run an offline intermediary server ?
0
 
LVL 22

Accepted Solution

by:
yo_bee earned 500 total points
ID: 40331727
0
 

Author Closing Comment

by:CaussyR
ID: 40331991
Thank you for all your help, great articles.
0
 
LVL 22

Expert Comment

by:yo_bee
ID: 40332305
NP.
I have the two tier setup in my environment as followed by the articles.
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question