Skip to Content
Mastering Active Directory
book

Mastering Active Directory

by Dishan Francis
June 2017
Beginner to intermediate
742 pages
18h 29m
English
Packt Publishing
Content preview from Mastering Active Directory

The two-tier model

This is the most commonly used PKI deployment model in corporate networks. By design, the root CA needs to keep offline, and it will prevent the private key of the root certificate from being compromised. Root CAs will issue certificates for subordinate CAs, and subordinate CAs are responsible for issuing certificates for objects and services:

If a subordinate CA's certificate expires, the offline root CA will need to bring online to renew the certificate. Root CA doesn't need to be a domain member, and it should be operating in a work-group level (a stand-alone CA). Therefore, the certificate enrollment, approval, and renewal ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Mastering Active Directory

Mastering Active Directory

Dishan Francis
Active Directory, 5th Edition

Active Directory, 5th Edition

Brian Desmond, Joe Richards, Robbie Allen, Alistair G. Lowe-Norris

Publisher Resources

ISBN: 9781787289352Supplemental Content