Re: Difference between Certificate Authorities
- From: "Neeraj Mehra" <mehra.neeraj@xxxxxxxxxxx>
- Date: Sat, 1 Aug 2009 13:17:42 +0530
Hell,
thanks for your reply.
I got your point but my main concern is:
If my Enterprise Root is crashed then certificate issue by Enterprise root
CA will be served by Enterprise Sub Ordinate CA.
Regards
Neeraj Mehra
"Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx> wrote in message
news:697E4AE8-BF62-446A-90B6-CDD3C6F22904@xxxxxxxxxxxxxxxx
Hi
- A Root CA is the first CA to be created and has NO CA above.
- Enterprise CA is a CA that is in an AD Domain and provides unique
features (like auto enrollment) to that forest/domain.
You're comparing 2 distinct things.
- Enterprise CAs Vs Standalone CAs - (the first one is in a domain and
published in your AD, the second one may be in a domain or not but is not
published in your Active Directory domain and does not provide auto
enrollment)
- Root CAs Vs Subordinate Vs Issuing CAs. Root CAs are in the top of the
hierarchy, bellow that CA you can have a hierarchal structure of many
subordinate/issuing CAs that perform specific certificate related jobs.
For instance you could have a hierarchy like this:
Standalone Root CA -> Standalone Subordinate CA -> Enterprise Issuing CA.
The first CA is in a workgroup, the second CA is in a Workgroup the third
CA is in your domain. Of course the 1 and 2 CA could be in your domain as
well, but only the Enterprise CA can perform auto enrollment for your
users/computers that belong to the domain where the Enterprise CA is at.
--
I hope that the information above helps you.
Have a Nice day.
Jorge Silva
MVP Directory Services
"Neeraj Mehra" <mehra.neeraj@xxxxxxxxxxx> wrote in message
news:ue$Ff1SEKHA.3556@xxxxxxxxxxxxxxxxxxxxxxx
Hello,
What is difference between Enterprise Root CA and Enterprise Sub ordinate
CA.
Regards
Neeraj Mehra
.
- Follow-Ups:
- Re: Difference between Certificate Authorities
- From: Jorge Silva
- Re: Difference between Certificate Authorities
- Prev by Date: Re: CAN I RENAME ADMINISTRATOR DOMAIN ACCOUNT
- Next by Date: Re: Disable admin from Debug program GP policy
- Previous by thread: Re: CAN I RENAME ADMINISTRATOR DOMAIN ACCOUNT
- Next by thread: Re: Difference between Certificate Authorities
- Index(es):
Relevant Pages
|