NDES Role on CA


hi all,

i'm looking deploy ndes in our environment , i've read conflicting info whether installing on ndes role on enterprise ca supported or not.

for example:

on technet blog, suggested ndes role can installed on same box enterprise ca: http://blogs.technet.com/b/askds/archive/2010/11/22/ipad-iphone-certificate-issuance.aspx

on technet article, recommeneds installing ndes role on separate box enterprise ca, if ca standalone, ok have ndes service on same box: http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs.aspx

on technet guide, guide pretty same above: http://technet.microsoft.com/en-us/library/ff955646(v=ws.10).aspx

so can ndes role on same box enterprise ca? reasons separate role? reasons why there difference in direction between deploying enterprise ca environment , standalone ca environments?

thanks,
dave.k

you can install on same server or on different server technically.

personally, never recommend this. not having iis-based services installed on ca in medium large size org. there many iis-related vulnerabilities on years affect ca.

brian



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group