I'm setting up Certificate Services for internal use in our AD domain which has a parent / child domain structure. The parent domain contains only DC accounts. All clients and users are housed in the child domain. I have built an offline root CA without issue following a TechNet guide. The next thing I need to do is build the subordinate CA to issue the certificates - no issues with doing this but where do I place it ? Should it be in the parent domain or should it be in the child domain or do I need to build two subordinate CAs one in each domain ? Your advice will be greatly appreciated !