Solved

Certificate Authority - Server 2012 R2

Posted on 2014-12-17
2
119 Views
Last Modified: 2014-12-18
We just upgraded our domain controllers to 2012 R2.
I noticed we do not have a certificate authority in our environment.

Do we need one, and what are the ramifications if we do not have one in the environment.

What is best practice?

Thanks
0
Comment
Question by:techgenious
2 Comments
 
LVL 56

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 40504936
You may or may not need a CA for your environment. That is entirely about your environment itself. As an example, does everyone need a file server?  Many networks do. But those that are heavily cloud-centric may be using OneDrive for Business or DropBox Business and a file server has no benefit.  This is true for almost every role, and ADCS is no different. There are some use cases for an internal CA, and there are some environments  where it'd offer no benefit whatsoever.

As with any network planning, start with what you want to do, then pick the services that get you there. If nothing you want requires a CA, don't install ADCS anywhere. If something you want has a PKI dependency, or if a role explicitly requires a CA, you'll find out quickly during your planning.

-Cliff
0
 
LVL 4

Expert Comment

by:akalyan911
ID: 40505071
it is depend on your domain environment, You can install the AD - Certificate Services if is required. without installation also you can work out..

AD CS starting in Windows Server 2008 provides customizable services for creating and managing public key certificates used in software security systems that employ public key technologies ... in your environment is small and not having much software application, i would suggest you to not install..

you can go through the Microsoft Technet articles from more information..
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Table of Contents: Lesson 1 - Installing Windows Server 2012 (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2012/A_11592-Become-an-Administrator-Installing-Windows-Server-2012.html) Lesson 2 - Configuring Ser…
I don't know if many of you have made the great mistake of using the Cisco Thin Client model with the management software VXC. If you have then you are probably more then familiar with the incredibly clunky interface, the numerous work arounds, and …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now