Experts,
I am no expert on PKI although I've setup a couple for simple uses.
I have a client that has a single Enterprise root (single tier). They have server 2008 and are also looking to upgrade AD to 2016 while taking my recommendation to upgrade to 2 tier PKI (one offline root and 2 SUB Issuing).
I understand the theory behind it but I could use some guidance on getting it done. I've looked at several articles but nothing that's detailed on this scenario.
thinking I would just build out the PKI on 2016 separate as i know you can have multiple PKIs in the same forest (a good guide on this might be helpful also).
But what needs to be copied over/moved to new PKI from old? GPO changes ect.
Should PKI be done before AD or does that matter?
I'm not overly familiar with this client so I'm not really sure what they use certificates for at this point.
Our community of experts have been thoroughly vetted for their expertise and industry experience.
This award recognizes a member of Experts Exchange who has made outstanding contributions to the community within their first year as an expert. The Rookie of the Year is awarded to a new expert who has the highest number of quality contributions.
The Distinguished Expert awards are presented to the top veteran and rookie experts to earn the most points in the top 50 topics.