Remove a root domain CA and keep authenticating to a windows domain


hello everyone,

we have windows domain 3 different domain controllers, windows server 2003 r2. inside domain have ca (with windows 2000) used vba code signing , clients hosts authenticate domain.

since not signing vba projects anymore, remove ca server , use self-signed certs in order login domain.

is procedure correct? possible configure domain without root ca?

if who's in charge of issuing these certs?

kind regards.

hi,

in domain users authenticated dc, users access resources if have permissions resources(using acls). kind of kerberos authentication.

with ca more, such smart cards, providing customizable services issuing , managing public key certificates used in software security systems employ public key technologies. or generate self signed certificates , rid of messages services not being trusted.

for more information, please refer below link:

http://technet.microsoft.com/en-us/library/cc731564(v=ws.10).aspx

regards,

yan li


cataleya li
technet community support



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group