Enterprise CA (SHA1 & SHA2 Co-existing)


we have pki infra in ad,  ent rootca + 2 ent subordinate ca (all ad integrated) in sha1 mode-os windows 2008 r2.

is technically viable create 1 more ent root ca + 2 subordinate ca , sha2 infra, in same ad domain?

in short , co-existence possible 2 ent root cas , 2 sub cas(2 subordinates each 2 ent root ca) in single ad domain?

yes, can have multiple enterprise root cas , additional subordinate cas linked root.

here quote coexistence ms document on sha-2 deployment: "currently, having 2 pki trees, 1 sha-1, 1 sha-2, safest option many organizations, highest cost option. organizations choosing 2 tree design until can ensure needed critical applications , devices can accept sha-2. "

http://social.technet.microsoft.com/wiki/contents/articles/31296.implementing-sha-2-in-active-directory-certificate-services.aspx#microsoft_s_sha-1_deprecation_policy

also previous forum posting:

https://social.technet.microsoft.com/forums/windowsserver/en-us/796c9e93-c25d-46c5-bd7e-a54afb3b3264/multiple-root-cas-in-single-forest-single-domain?forum=winserversecurity


byron wright (http://byronwright.blogspot.ca)



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS