Enterprise CA (SHA1 & SHA2 Co-existing)


we have pki infra in ad,  ent rootca + 2 ent subordinate ca (all ad integrated) in sha1 mode-os windows 2008 r2.

is technically viable create 1 more ent root ca + 2 subordinate ca , sha2 infra, in same ad domain?

in short , co-existence possible 2 ent root cas , 2 sub cas(2 subordinates each 2 ent root ca) in single ad domain?

yes, can have multiple enterprise root cas , additional subordinate cas linked root.

here quote coexistence ms document on sha-2 deployment: "currently, having 2 pki trees, 1 sha-1, 1 sha-2, safest option many organizations, highest cost option. organizations choosing 2 tree design until can ensure needed critical applications , devices can accept sha-2. "

http://social.technet.microsoft.com/wiki/contents/articles/31296.implementing-sha-2-in-active-directory-certificate-services.aspx#microsoft_s_sha-1_deprecation_policy

also previous forum posting:

https://social.technet.microsoft.com/forums/windowsserver/en-us/796c9e93-c25d-46c5-bd7e-a54afb3b3264/multiple-root-cas-in-single-forest-single-domain?forum=winserversecurity


byron wright (http://byronwright.blogspot.ca)



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com