August 2019
Intermediate to advanced
786 pages
20h 22m
English
This is the most commonly used PKI deployment model in corporate networks. In this design, the root CA is kept offline. It will help to protect the private key of the root certificate from being compromised.
Root CAs will issue certificates for subordinate CAs, and subordinate CAs are responsible for issuing certificates for objects and services:

If a subordinate CA's certificate expires, the offline root CA will need to be brought online to renew the certificate. The root CA doesn't need to be a domain member, and it should be operating at the workgroup level (a standalone CA). Therefore, the certificate enrollment, approval, ...