Solved

How do I configure a Windows 2008 R2 Subordinate Certificate Server ?

Posted on 2014-09-17
5
264 Views
Last Modified: 2014-09-19
Hi everyone,

I am in the process of implementing a PKI environment. I have configured and created a CA root server.  I need this to be a 3 tier PKI infrastructure.  How do I create a subordinate server ? Do I export the root CA certificate and import it in to the subordinate server ?  I have read many articles but its just confusing...information overload.
0
Comment
Question by:CaussyR
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 40330161
that is correct you also have to create and enable a certificate request from the subordinate CA to the root ca and authorize the request and from the root ca export the certificate.  also you should create a group policy that adds the root certificate to the trusted root certificate store on all of the machines.

you can now shutdown the root certificate server.  the root ca should not be domain joined. preferably in a virtual machine.
0
 

Author Comment

by:CaussyR
ID: 40331363
Thanks David.

I have been looking for step-by-step instructions to build an offline intermediate server but can not find anything.  Please, could you let me know how to build an offline intermediate server ?

I have seen some documentation but this discusses running the certutil command line etc - is this required to run an offline intermediary server ?
0
 
LVL 23

Accepted Solution

by:
yo_bee earned 500 total points
ID: 40331727
0
 

Author Closing Comment

by:CaussyR
ID: 40331991
Thank you for all your help, great articles.
0
 
LVL 23

Expert Comment

by:yo_bee
ID: 40332305
NP.
I have the two tier setup in my environment as followed by the articles.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question