Multiple enterprise subordinate CAs in one domain


lets imagine have following pki stucture – 1 root ca (standalone) , 2 enterprise cas. 1 of these enterprise ca‘s has domain controller authentication template published , other doesn‘t. may domain controllers autoenroll certificates according template time time. question – domain controller able find correct ca in ad  domain controller authentication  template enabled , able autoenroll certificate? affraid can stuck on ca template disabled , fail autoenrollment l thanks.

no, domain controller find ca template published , able enroll against template.


paul adare cto identit inc. ilm mvp


Windows Server  >  Security



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

DFSR RPC replication errors 5014 1726 with large files over VPN

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B