Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Can a 2003 ADCS Enterprise Subordinate CA be started offline?

$
0
0

Hello,

We are preparing to retire a PKI hierarchy based on Win2003 ADCS.  We are being asked to be able to query the subordinate CA certificate database if, years in the future, we are challenged about a signature created by one of our certificates (we need to be able to demonstrate when the cert was issued, expired, revoked, etc).  

Can an enterprise sub CA service start somehow without being able to bind to AD (and possibly no network connection at all)?  Otherwise, is there a way to query a CA database using certutil or another tool without the CA service being started?


Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>