Solved

How do I configure a Windows 2008 R2 Subordinate Certificate Server ?

Posted on 2014-09-17
5
252 Views
Last Modified: 2014-09-19
Hi everyone,

I am in the process of implementing a PKI environment. I have configured and created a CA root server.  I need this to be a 3 tier PKI infrastructure.  How do I create a subordinate server ? Do I export the root CA certificate and import it in to the subordinate server ?  I have read many articles but its just confusing...information overload.
0
Comment
Question by:CaussyR
  • 2
  • 2
5 Comments
 
LVL 79

Expert Comment

by:David Johnson, CD, MVP
ID: 40330161
that is correct you also have to create and enable a certificate request from the subordinate CA to the root ca and authorize the request and from the root ca export the certificate.  also you should create a group policy that adds the root certificate to the trusted root certificate store on all of the machines.

you can now shutdown the root certificate server.  the root ca should not be domain joined. preferably in a virtual machine.
0
 

Author Comment

by:CaussyR
ID: 40331363
Thanks David.

I have been looking for step-by-step instructions to build an offline intermediate server but can not find anything.  Please, could you let me know how to build an offline intermediate server ?

I have seen some documentation but this discusses running the certutil command line etc - is this required to run an offline intermediary server ?
0
 
LVL 22

Accepted Solution

by:
yo_bee earned 500 total points
ID: 40331727
0
 

Author Closing Comment

by:CaussyR
ID: 40331991
Thank you for all your help, great articles.
0
 
LVL 22

Expert Comment

by:yo_bee
ID: 40332305
NP.
I have the two tier setup in my environment as followed by the articles.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OfficeMate Freezes on login or does not load after login credentials are input.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now