June 2017
Beginner to intermediate
742 pages
18h 29m
English
This is the most commonly used PKI deployment model in corporate networks. By design, the root CA needs to keep offline, and it will prevent the private key of the root certificate from being compromised. Root CAs will issue certificates for subordinate CAs, and subordinate CAs are responsible for issuing certificates for objects and services:

If a subordinate CA's certificate expires, the offline root CA will need to bring online to renew the certificate. Root CA doesn't need to be a domain member, and it should be operating in a work-group level (a stand-alone CA). Therefore, the certificate enrollment, approval, and renewal ...