Existing two-tier enterprise online to two tier, root offline

I have went through many standalone to two tier discussions/forums, but found nothing conclusive on this topic.
I have inherited a online two tier architecture, and would like to implement some best practice work:
first step is to place the root CA offline. Based on what I have read I can do that by backing up current enterprise online root CA.
Then to install new root standalone CA on virtual box (switching to virtual) and use the onlines public key and same hostname to install the standalone. Make sure CRLs are placed on reachable network drive and so on...
The issuing CA will be the same. Nothing will change...other than adding additional later on.
Did I get this correct? Or will I have to reissue the root CA and have it be trusted on all firewalls/load ballancer, ect and reissue? Also we are pushing to two factor authentication with AD and cert based and I need to make sure I have my back-end ready. 
If i go early ahead and implement user cert templates with current architecture, can I take root offline later and everything still will be in tact?

In a properly deployed PKI, the offline root CA is offline from build time. You should not be converting an enterprise root CA to a standalone root CA (how do you guarantee that the private key was not compromised prior to transition).
There is no way this would pass any form of audit (for example).
It sounds like you are early in the process, I recommend that you start over again and do it with a proper offline root CA.
Follow the steps in this link: http://technet.microsoft.com/en-us/library/hh831348.aspx
Brian

Similar Messages

  • Two separate enterprise WiFi networks in the same building

    I work in a building that currently has Cisco controller based access points. The access points aren't managed by us and are actually part of another campus. We are given access to them but they don't work quite like we want them to. So we are wanting to bring in our own Cisco WLC 2504 with 3702 APs. But when we brought this up with the main campus they said we can't have two separate enterprise wireless networks in the same building. That their APs will mark our APs as rogues and try to shut them down. There was also mention that they can't share the same channel and that the radios will negotiate with each other to determine how much power they need for coverage. But from what I've read none of that is true. So maybe I misunderstanding something and hoping someone here with more experience can shed some light on this. The only reason we would want to keep their wireless in the building is so when their staff come to our office they can use it. 
    So can two separate WLC/AP systems on different subnets and broadcasting different SSIDs exist in the same building with out causing any issues?

    By default, the WLC code does not try to contain rogue AP's.  Just lots of alarm's and unclassified rogue's.
    In this case you hosts may have actually enabled containment but would have also received a screen full of warning about the public nature of the unlicensed wifi band.
    Here the Superior Court system is side by side with the County system even to the extent that the AP's are next to each other.  Gets fun.  Since each SSID constitutes a rogue, each unit represents a LOT of rogues to report.
    Good Luck

  • How can i pay on the apple store online with two credit cards, with two different billing addresses

    I will be greatful if you could answer me this question...
    How can i pay on the apple store online with two credit cards, with two different billing addresses?
    I know that you can use two credit cards to pay an item but the problem is that i can only put the billing address of just one of the credit cards, and since the two cards are from different people (my parents) i can't do it. They live in the same place so i don't know if i should just put one of the billing address.
    Thank you.
    PS. I don't know if this is the right community to ask this, sorry if i'm wrong.

    On the Apple Store "Payment & Pricing" page it states:
    Using more than one payment card
    You can also combine payment methods to pay for your purchase. Choose from the following combinations of credit cards and Apple Gift Cards:
    Credit card(s) - up to two
    Apple Gift Card(s) - up to eight
    Apple Gift Card(s) + one credit card
    During checkout, if you are paying with a gift card issued by a credit card company, you can combine it with one credit card.

  • In outlook 13, How can I get my new mail to populate my existing "account" or "Profile" instead of two separate ones-reposted, maybe first was wrong place

    I set up outlook, using mainly wizards. I have received some mail from my provider account.
    trying to get data from my old pc, I accidently set up another account, it became default.
    I finally got it deleted
    I now have my first profile with email I received, and all data (contacts, emails and archived items) but now I can not get new email.
    I tried to "change settings" but there is no account listed to chose to change.
    I create new and again I have two accounts.
    How can I get my new mail to populate my existing "account" or "Profile" instead of two separate ones or
    How to set up completely new, and move everything from existing profile to it and get rid of existing, Just do not want two.
    Thank you so much.

    They can help you over here.
    http://answers.microsoft.com/en-us/office/forum/office_2013_release-outlook?sort=lastreplydate&dir=desc&tab=Threads&status=&mod=&modAge=&advFil=&postedAfter=&postedBefore=&threadType=All&tm=1387249501544
    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

  • In outlook 13, How can I get my new mail to populate my existing "account" or "Profile" instead of two separate ones

    I set up outlook, using mainly wizards. I have received some mail from my provider account.
    trying to get data from my old pc, I accidently set up another account, it became default.
    I finally got it deleted
    I now have my first profile with email I received, and all data (contacts, emails and archived items) but now I can not get new email.
    I tried to "change settings" but there is no account listed to chose to change.
    I create new and again I have two accounts.
    How can I get my new mail to populate my existing "account" or "Profile" instead of two separate ones or
    How to set up completely new, and move everything from existing profile to it and get rid of existing, Just do not want two.
    Thank you so much.

    You can open your second profile which is no ability of receiving new mail and export all of messages/contacts/calendar item to a PST file and save it somewhere.
    Then open the first profile, import the privious PST file into this profile to solve the problem.
    Using .pst files in Microsoft Outlook is good way to transfer the data, here is some information how to manage the PST file for your reference.
    http://support.microsoft.com/kb/287070/en-us
    Tony Chen
    TechNet Community Support

  • Could you tell me if it would be supported to pair a two node enterprise edition front end pool inc mirror sql with a one node enterprise edition front end pool inc single sql?

    Hi all,
    Could anyone tell me if it would be supported to pair a two node enterprise edition front end pool inc mirror sql with a one node enterprise edition front end pool inc single sql?
    MUCH THANKS.

    The answer from TechNet found at http://technet.microsoft.com/en-us/library/jj204697.aspx Is, and I quote:-
    Enterprise Edition pools can be paired only with other Enterprise Edition pools. Similarly, Standard Edition pools can be paired only with other Standard Edition pools.
    Also, "Neither Topology Builder nor topology validation will prohibit pairing two pools in a way that does not follow
    these recommendations. For example, Topology Builder allows you to pair an Enterprise Edition pool with a Standard Edition pool.
    However, these types of pairings are not supported."
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"

  • Two Separate Mail Accounts w/Two Separate Address Books?

    I want to set up two separate mail accounts with two separate address books. I've been using Mail for several years and love it. My wife has been with AOL but now wants to move to Mail.
    Is there a way to have two separate accounts, two address books, and two separate Mail icons to click to open, so we aren't tempted to look at each other's incoming/outgoing mail? Also, our address books are very different and we'd rather not intermingle them.

    Hi StacheCache!
    She could also retrieve her AOL Email online, without a separate User Account on your shared Mac.
    She would log in to AOL Webmail using her AOL Screen Name and password.
    ali b

  • I have two separate itune accounts under two different email accounts and would like to combine them under one account.  Is this possible and if so, how do I do it?

    I have two separate itune accounts under two different email accounts and would like to combine them under one account.  Is this possible and if so, how do I do it?

    If you go to Settings > iTunes & AppStore , you can sign out from your account, and sign in with the one you've used to purchase apps.This will not remove any apps you already have on it.
    Then you can go to AppStore and download apps you've purchased (either via "Purchased" button in "Updates", or simply search for them and download them.
    That way you can have multiple accounts' apps on your iPad. When updating, you will be prompted for the credentials for account you've purchased given App with.

  • We have two apple ID's and two libraries.  My daughter's IPOD is syncing with my library and I need to change this, but I can't figure out how.

    We have two apple ID's and two libraries.  My daughter's iPOD is syncing with my library and we really want to go to just one library--Mine for ease and we can't figure out how to do it.  Please help!!!

    Apple does not transfer content bought with one Apple ID to another Apple ID. Apple will not merge two Apple IDs.
    If most of your content was bought with the Yahoo! Apple ID but you now want the Gmail address for your Apple ID, the trick will be to change the address used for the Yahoo ID with the Gmail address. However, to do that you must first free the Gmail address from that other Apple ID. Use the instructions from Apple to substitute another address that is not used as an Apple ID for your Gmail address in the Apple ID with the Gmail address. Then, when the Gmail address is no longer used in an Apple ID, you can use the same instructions to substitute the Gmail address for the Yahoo address in the Apple ID with the Yahoo address.
    Changing the email address you use for your Apple ID -
    http://support.apple.com/kb/HT5621

  • How to use two different ojdbc14.jar for two web application.

    Hi,
    I have two web application running in same tomcat, I need to use the two different ojdbc14.jar for two application, now both are taking the jars from tomcat common/lib directory, I tried copying the new ojdbc14.jar in web-inf/lib folder of one application, but it is not working.
    Could you please let me know whether this will take the jar from tomcat by befault or from web-inf, and a solution how to proceed with this.
    Thanks in advance.

    Yes, I tried removing the jars from common/lib, but as the connection string is mentioned inside the server.xml it is showing db connection error while trying to connect to the database

  • I have two separate iTunes libraries on two separate Computers. I need to consolidate them so I can play them on a brand new computer. How do I do this so I can play them off an External Hard Drive on my brand new computer?

    I have two separate iTunes libraries on two separate Computers. I need to consolidate them so I can play them on my brand new computer. How do I do this so I can play them off an External Hard Drive on my brand new computer?

    Why, if it told you you have insufficient space on your computer, would it suggest making more space available on your phone?
    At a guess, you have insufficient space on your phone. Installing software will typically require more space than the final size of the software, perhaps even twice or three times as much, for the installation process. You can easily dump some videos or music temporarily, and then synch them back in afterwards.

  • I have two different 5s's with two different phone numbers but they are both using the same iCloud/apple account. After upgrading to iOS8 when I get a phone call on one phone both phones ring.

    I have two different 5s's with two different phone numbers but they are both using the same iCloud/apple account. After upgrading to iOS8 when I get a phone call on one phone both phones ring. One phone is for work and one is for private and I don't need both phones to ring from one call. It's bizarre.......is this supposed to be like this? If so where can I turn it off?? And while we are at it iOS8 has installed iBooks on both of my phones and iTunes won't let me uninstall it. I don't need or want iBooks on my phones.

    Hi,
    There are two easy fixes to this.
    One, you can set up Family Sharing, in which you can have two different iCloud Accounts, yet still share the same apps, music, media etc.
    Two, go to Settings and turn-off "Handoff". This can be found under the General page.
    Hope this helps!

  • Can i have two internet connections connected to two airport extremes separately without disturbing the home sharing option.

    can i have two internet connections connected to two airport extremes separately without disturbing the home sharing option. i want to have both the airport extremes to use a single imac for streaming music or video to my apple tv's at different places where one apple tv is in the range of one airport extreme.it's not a problem if both airport extremes have different wifi id's with separate internet.The imac which i use for streaming the music and videos is only in the range of only one airport extreme.is it possible if i can stream music or videos to my apple tv which is not in the range of same airport extreme which i use for imac but in the range of other airport extreme.
    Finally what i need is i want to use two internet networks as my highest possible internet bandwidth is about 1mbps.and i know that i cant mix both the networks and make it as 2mbps.

    Yes, that is possible. Please check out the following Apple Support article for details on how.

  • I would like to import two different cf cards from two different cameras into the same project/folder and have them be in order of the times they were taken, is there a trick?

    I would like to import two different cf cards from two different cameras into the same project/folder and have them be in the order of the times they were taken, any ideas on how to do this?

    Just import them normally and sort the project by date. They will fall into place. If you tried this and it isn;t happening then make sure the data and times on the two cameras are identical and make sure you are sorting by date and time and nothing else.

  • How can I implement two TCP/IP servers (on two separate machines) and one TCP/IP client (on third machine)

    I have an application where I need to send data via TCP/IP from two separate machines to a third machine. The machines are on a local area network connected through a network switch. The data are generated independently through data acquisition by the two independent machines before are sent to the client on third machine. Each machine has one network card. Thanks.
    Solved!
    Go to Solution.

    If you have three separate machines, you don't need to use separate ports.  They will have three IP addresses.
    Remember this rule: TCP connections are EXACTLY like telephone connections.
    Have your client open two connections: same port on two different IP addresses.
    Each client listens for connections.
    After connections are established, you get to decide the protocol:  maybe the client should explicitly ask for data, maybe the servers just dump it without being asked. It's up to you.
    Read this:
    TCP tips and tricks
    Steve Bird
    Culverson Software - Elegant software that is a pleasure to use.
    Culverson.com
    Blog for (mostly LabVIEW) programmers: Tips And Tricks

Maybe you are looking for

  • I have installed axis but i get the following error java.util.MissingResour

    i have installed axis and i get the following error when i try to acces from http://localhost:8080/axis/axis/index.jsp java.util.MissingResourceException: Can't find bundle for base name i18n, locale en_US      java.util.ResourceBundle.throwMissingRe

  • Split Hard drive  - MAC/PC

    a friend divided up my hard drive to allow me to run windows on my macbook pro. windows was never updated or used so i would like to get rid of the PC part of my hard drive and return it all to one larger HD for mac. Can anyone help me as to how i do

  • IPhone 5 Battery & Data usage issues

    Here's my journey. I had the iPhone 5 from the day it was realeased. Was with Vodafone Australia. Phone was awesome. Coverage was an issue, so decided to swap to Telstra recently. Got new iPhone 5 with the change over. From the beginning, the new Iph

  • Integration Stellent 7.5 with MS SharePoint. Is it possible?

    Hi there, I need to integrate Stellent 7.5 with MS SharePoint 2007. Can you use Web Parts product to integrate Stellent 7.5 with Microsoft SharePoint Server 2007 ? Thanks

  • [ProjectServer 2013] Resource authorization data lost on PSI Resource Update

    Hi, as the title says I noticed that sometimes resource authorization data of a resource/user is lost in ProjectServer 2013 on a PSI resource update. Since it did not happen every time for every resource (user) I tried to investigate this issue in mo