Publication Locations for AIA and CDP
i following guide demonstrared publishing offline root ca's cdp , aia http locations iis on sub ca , publish aia , cdp of sub ca external http server.
does work or should offline root ca's cdp , aia point external web server?
1) never install iis on subca (i not want anonymous http requests coming cas)
2) publish offline root ca's certificate , base crl group of web servers (behind hw load balancer) both internally , externally accessible using *same* url
3) publish issuing ca certificates, base crls, , delta crls group of web servers (behind hw load balancer) both internally , externally accessible using *same* url
brian
Windows Server > Security
Comments
Post a Comment