Certificate Services - AIA, CRL HTTP placement?
hello everyone,
i have design question regarding 2 tier pki. want build pki standalone root ca (offline), enterprise issuing ca1 (first forest), enterprise issuing ca2 (second forest).
ca1 , ca2 should separated each other.
i want have aia , crl of standalone root ca published on both ldap , http.
i have http://pki.first-domain.local/... ca1 and http://pki.second-domain.local/... ca2. somehow possible? based on extensions variables seems it's not possible. recommended approach this? safe put crl , aia root ca ldap / there consequences?
suggest check blog post outlines recent best practices on designing cdp , aia extensions: designing crl distribution points , authority information access locationshello everyone,
i have design question regarding 2 tier pki. want build pki standalone root ca (offline), enterprise issuing ca1 (first forest), enterprise issuing ca2 (second forest).
ca1 , ca2 should separated each other.
i want have aia , crl of standalone root ca published on both ldap , http.
i have http://pki.first-domain.local/... ca1 and http://pki.second-domain.local/... ca2. somehow possible? based on extensions variables seems it's not possible. recommended approach this? safe put crl , aia root ca ldap / there consequences?
vadims podāns, aka powershell cryptoguy
weblog: www.sysadmins.lv
powershell pki module: pspki
check out new: ssl certificate verifier
check out new: powershell file checksum integrity verifier tool.
Windows Server > Security
Comments
Post a Comment