Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Setup of Multiple Issuing CA's

$
0
0

There are lots of comments regarding the use of multiple Issuing CA's in an ADCS infrastructure, even comments about you need multiple Issuing CA's with Server 2003 to achieve resiliency. However, there does not appear to be any whitepapers or technical detail about how to set this up.

The only information I can find relates to setting up an Active/Standby architecture using failover clustering.

Is this the only way of achieving resiliency ?

Why are there comments regarding the use of multiple Issuing CA's if this is not possible ?

Currently our Issuing CA is deployed as a virtual machine so already has failover capability which safeguards against physical hardware failure.

We don't currently have applications which need live authentication of certificates, but this is due to change.

Is it the CRL's that are important here or do you really need multiple Issuing CA's ?

As I mentioned above there are lots of comments about having multiple Issuing CA's but nothing which discusses setup for this model.

Help please.


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>