Questions about CA type, best for my environment?


hello, 

i need bring ca in customers domain.  they need ldaps, nothing else.  i have been reading , appears easiest way install on dc ldaps ready go.  i have few questions.

1:  does installing on dc in ad mode cause changes should concerned with? can merely installing cause problem?

2: reading says, don't install on dc.  i thinking of installing standalone ca issuing cert dc.  is strategy?  as standalone ca able out if want use ad integrated ca in future?  does installing standalone ca pose problem?

3:  in future, if want whole multi-tier pki, won't hard out of minimal installation right?

thanks!

with small of need - might easier , less of headache commercial cert. installing own ca possibility, ever time see small requirement this, inevitably gets ignored , forgotten until breaks , causes bigger headache. 

mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years.



Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group