ADCS High Availability and Redundacy


hi there,

i have general question regarding adcs redundacy , high availability on our customer.

our customers have 2 tier windows server 2008 r2 ca 1 stand alone root ca , 1 enterprise sub ca (issuer) @ same site (drc), want implement 1 enterprise subca (issuer) again on site (dc) cross site ha/redudancy enterprise sub issuing ca. i know adcs can installed ha service in failover cluster in windows server 2008 r2. however, if there not need level of ha, there redundancy if 2 issuing ca`s set exact same certificate templates published?

  1. is possible & steps should prepare?
  2. i.e. autoenrollment try next available ca if first 1 unavailable?

many help.


hi fajar pambudi,

microsoft not recommend install “active directory certificate services” on server has been installed roles on it. highly advise install “active directory certificate services” on member server has not been installed role or application.

microsoft supporting clustered configurations of ca service. clustering not supported other ca role services online certificate status protocol (ocsp), or microsoft simple certificate enrollment protocol (scep).

you may cluster enterprise subordinate ca after redesign ca environment.

back certification authority : http://technet.microsoft.com/en-us/library/cc725565.aspx

preparing ca cluster environment

http://technet.microsoft.com/zh-cn/library/cc742448(v=ws.10).aspx

installing , configuring ca cluster

 http://technet.microsoft.com/en-us/library/cc742450(v=ws.10).aspx

failover clustering , active directory certificate services

https://gallery.technet.microsoft.com/failover-clustering-and-b3ea8858

i’m glad of you!


we trying better understand customer views on social support experience, participation in interview project appreciated if have time.
helping make community forums great place.



Windows Server  >  High Availability (Clustering)



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS