> 1. Not sure.
Does that mean it doesn't matter which one I put it on?

> 2. Not much will change on the LAN. If you are using Microsoft Certificate
> Services you should factor in backup/restore of the CA. Additionally, once
> you make a machine a MS Certificate Services server, you can no longer
> promote it to a DC (if it's a member server), nor demote it (if it's
> a DC)

Thats because the certs would become invalid if I did, isn't that right?

> 3. I would suggest an AD-integrated CA. This means that machines in your
> domain automatically trust the CA, and users using those machines (eg
> laptops) will not get a warning about the certificate being issued by an
> untrusted CA. That's a minor plus. The other alternatives are (a) buy an
> certificate from a trusted 3rd party vendor (eg Thawte, Verisign,
> or (b) have the users put up wth the warning or (c) manually install the
> CA's root cert into the user's certificate store

Both types can be AD integrated, the enterprise version is manditory, the
standalone will use it if available. But use it how?
I have seen a script to install the cert in the trusted zones and I can
certainly install them into each users machine manually if I had to so that
doesn't bother me too much. But which one are you referring to when you say
AD integrated? It sound like enterprise?

