If I have two Root CA in the same Domain, Do I have to configure two seperate locations for the CRLs

Hello All
Can someone please help me with the following question :)
I asked the question, can you have two Enterprise Root CA in the same AD domain. This question was kindly answered by Paul
here  the answer was Yes.
As far as I believe the two important aspects from a client point of view (e.g. IE on Windows 7 PC for example) are
1: Public key of the CA (e.g. the CA cert published in AD and therefore downloaded to the X509 store on your PC)
2:  CRL (published via LDAP (in Configuration partition of AD), HTTP/S or File Share)
I believe as long as you have access to the above two you can turn the CA off if you want.
I believe the location of the CRL is detailed in the CDP which is detailed on the Certs issued but a given CA, so the client can look in the Cert and see what it states about the CDP and thereby get the list of revoked certs.
If all of the above is correct?
when I add a second Root CA to the same Domain, do I need to use a CA setup file (e.g. the text file, I believe with a .inf extension) to tell the CA setup routine to place its CDP at a location other than the  default location in case it overwrites
the existing CRL at the default location. Basically I do not want to overwrite (delete) the current CRL when installing another Root CA or does the fully qualified X500 name of the CDP include the CA Name (and therefore be unique) and it will not over write
the original?
Thanks All
AAnotherUser__
AAnotherUser__

> I believe as long as you have access to the above two you can turn the CA off if you want.
Enterprise CAs are not intended to be offline. Therefore, you should not turn off them. If these root CAs issue certificates only to subordinate CAs, then you should consider to implement offline Standalone (not Enterprise) Root CAs.
> I believe the location of the CRL is detailed in the CDP which is detailed on the Certs issued but a given CA, so the client can look in the Cert and see what it states about the CDP and thereby get the list of revoked certs.
this is correct.
> to place its CDP at a location other than the  default location in case it overwrites the existing CRL at the default location
no, CDP locations should be defined in the post-installation script.
> does the fully qualified X500 name of the CDP include the CA Name (and therefore be unique) and it will not over write the original
yes, LDAP URL includes CA server's NetBIOS name to differentiate between CAs.
My weblog: en-us.sysadmins.lv
PowerShell PKI Module: pspki.codeplex.com
PowerShell Cmdlet Help Editor pscmdlethelpeditor.codeplex.com
Check out new: SSL Certificate Verifier
Check out new:
PowerShell FCIV tool.

Similar Messages

  • I have bought key note for my iPad 2 can I used the same in my mac or I need to buy them for the mac

    I have bought key note for my iPad 2 can I used the same in my mac or I need to buy them for the mac

    Sorry, no. Different Apps for different operating systems.
    Stedman

  • If i send a message from my mac it comes up as the same convo as my iPhone but starts a new convo for the receiver :S

    When i send a message from my mac it comes up as the same convo on my iPhone but starts a new convo for the receiving person, this is no good :S
    Any help?

    This is using the new Messages Beta by the way ^

  • I have two libraries on the same computer but different logins, there is my user account for the computer and then there is my grandma's, how do i get my music without having to resync on both libraries?

    this computer has two logins, my grandma's (which is the administrator) and mine, itunes is on both logins but on my login i have some music there and hers i have my other music.. i want to be able to redownload my music on my ipod touch with out having to resync back and forth between libraries.. how do i combine the libraries because if i go with one or the other i lose my music i have purchased, on both libaries the music belongs to me not my grandma,
    Also, a few weeks ago, I loaned the IPOD to somebody and they told me that evidently the IPOD had been hacked and that it had lost all the music.  When I got it back, I re-synced it and got some of the music back.  After talking to other people, I now suspect that my "friend" tried to do something he wasn't suppose to to and the IPOD shut down or that he was trying to create an Apple ID of his own without paying for it.  Now that I have it back, I just want to get the music back that I paid for that is already associated with my ID and that is in my two libraries.  I can see them in there (on the computer), I just can't access them to download  them on the IPOD.  Can you help?

    There are actually a few methods for using more than one iPod on a single computer: How To Use Multiple iPods with One Computer
    Just to summarise what's in the link above:
    Method one is to have two Mac or Windows user accounts which by definition would give you two completely separate libraries.
    Method two is to set your preferences so that either one or both iPods get updated with only certain playlists within one library. If you've had no success with this you can have a look through the guide on this page: Loading songs onto iPod automatically
    Another option when using a single library is to set one or both of the iPods to manual update: Managing content manually on iPod
    You can read about Windows user accounts here: Using Windows XP User Accounts

  • Please , I wonder if I can subscribe for more than one sync accout on the same Desktop? I mean that we are multi-users for the same desktop , so we need some privacy.

    I and my brothers and sisters use the same desktop , so we need to subscribe for more than a single sync account , and I don't know how. Thank you

    If you each have a separate Windows account then each of you should automatically have a separate Firefox profile.
    If you use the same Windows account (not much privacy in that case) then you will have to create a separate profile for each of you and a desktop shortcut to start each profile.
    * http://kb.mozillazine.org/Creating_a_new_Firefox_profile_on_Windows
    * http://kb.mozillazine.org/Shortcut_to_a_specific_profile
    * http://kb.mozillazine.org/Using_multiple_profiles_-_Firefox

  • I'm new to macs and I'm trying to connect my ipad to my mac to download music onto my ipad. i figured it was the same percedure as hooking a ipod to a pc. thanks for the help.

    im new to macs and im  having problems connecting my ipad2 to my mac pro. i figured that it was the same percedure as hooking a ipod to a pc.... thank for te help!

    Open iTunes with your iPad connected.  It should be listed in the Devices section of iTunes sidebar.  Select it.  You should now see a window with several tabs across the top.  You configure what you want synced under each tab, then sync.
    You can download a PDF or iBook version of the user guide here.  It contains detailed instructions on using the iPad, so I recommend you read it.

  • How can you set up your iphone 4s to show 2 seperate email address but that are on the same domain

    I have 2 email address linked to me on Outlook. one is a personal one for me and one is a group email address but both on the same domain.
    I have my own inbox set up on my iphone and i have tried to set up the group email address on my iphone, but because the credentials are the same, it is only bringing through my emails and not the one for the seperate email address - is there a way round this?
    Many thanks

    What do you mean "the credentials are the same"? The part of the email address before the @ should be different. If not then you do not have two different email addresses.
    Just go into the mail settings and choose add account. Enter the info for the second account. It won't matter that your incoming and outgoing smtp server are the same. If it did how could millions of people all use Yahoo or Google?
    If what you really have is one email account with a rule set to send specific emails to another folder, someone else will have to help you.

  • Window SBS server 2008 and window server 2008 R2 on the same domain

    Hi all,
    I am a person only work for linux system. Recently i work for my company that using microsoft technologie. So i have a lot of trouble. Could you please help me and below are my big troble that i have met:
    In my system, i have the first window SBS server 2008 run on our domain. However my organization growth up and we have more than 150 users and mailbox of exchange server 2007. So i do not want to use my sbs server 2008 anymore.
    I am going to install a window server 2008 R2 64 bit and join it into the same domain with sbs server 2008. It will be replicate the username, dns, OU and group policy...After that i will tranfer FSMO role to new server and i will demote then remove the
    sbs server.
    My boss say that i should not use this solution because window server sbs can not run with any other kinds of window server 2008 (R2, standard, enterprise...) and it will automatically shutdown the main server after a couple of days.
    Someone have experience can help me. I am so confuse now

    Maybe this will also help to better understand the steps involved:
    Transition from Small Business Server to Standard Windows Server
    http://blogs.technet.com/b/infratalks/archive/2012/09/07/transition-from-small-business-server-to-standard-windows-server.aspx
    Migrating away from SBS 2011
    http://social.technet.microsoft.com/Forums/en-US/07c58cc4-7d6d-419a-b1a0-439c2cc0c48d/migrating-away-from-sbs-2011?forum=smallbusinessserver
    Migrating from SBS 2008 to Windows Server 2012 R2 (NOT Essentials and with NO Exchange)
    http://social.technet.microsoft.com/Forums/en-US/1276d2d3-a8f2-4786-82f3-4308a2affb11/migrating-from-sbs-2008-to-windows-server-2012-r2-not-essentials-and-with-no-exchange?forum=smallbusinessserver
    And remember, as long as you don't move the PDC to one of the new DCs, you can leave the SBS 2008 up indefinitely. But I would remove Exchange 2007 off it right away once I've migrated the mailboxes and public folders, otherwise
    you will get yourself into an Exchange coexistence scenario which is much more complex to configure and support because of the CAS differences, changing the URLs on the old one to "legacy.domain.com," getting a new UC/SAN cert with the correct
    names on it, and more. Believe me, you really don't want to coexist them. The only time I've coexisted Exchange versions is during large migrations, such as 500 or more. Otherwise, I just migrate the mailboxes over a weekend and get it done with.
    Ace Fekay
    MVP, MCT, MCSE 2012, MCITP EA & MCTS Windows 2008/R2, Exchange 2013, 2010 EA & 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
    Microsoft Certified Trainer
    Microsoft MVP - Directory Services
    Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
    This posting is provided AS-IS with no warranties or guarantees and confers no rights.

  • HT5622 Can I have two apple id's on the same iPad. Example me and my spouse want to share the iPad but have different id's

    Can I have two apple id's on the same iPad. Example me and my spouse want to share the iPad but have different id's

    iOS does not support multiple users like a desktop OS does.
    You can use a web interface to your respective email accounts
    to keep things separate; but there is no provision for otherwise
    separating photos, media, etc.
    If you wish, you can contact Apple to let them know of your desire:
         www.apple.com/feedback

  • HT4314 I have two ipods in my house that were set up under the same email.  I have since assigned two different emails.  How can I change the game center account so that is not shared by both ipods because it is for two different users and they are not ha

    I have two ipods in my house that were set up under the same email.  I have since assigned two different emails.  How can I change the game center account so that is not shared by both ipods because it is for two different users and they are not happy?

    By "game center account", do you mean Apple ID?
    If so, you can change it.
    1. Tap settings and navigate to iTunes and App Stores
    2. Tap "Apple ID" and then tap "Sign Out"
    3. Log in with a different ID.

  • I would like to import two different cf cards from two different cameras into the same project/folder and have them be in order of the times they were taken, is there a trick?

    I would like to import two different cf cards from two different cameras into the same project/folder and have them be in the order of the times they were taken, any ideas on how to do this?

    Just import them normally and sort the project by date. They will fall into place. If you tried this and it isn;t happening then make sure the data and times on the two cameras are identical and make sure you are sorting by date and time and nothing else.

  • I have just signed upfor family sharing. Is there any way you can get the same app on two devices but not have to share it? My sons both want clash of clans but they don't want to be on the same village and they can't both be on app at the same time?

    I have just signed up for family sharing. Is there any way you can get the same app on two devices but not have to share it? My sons both want clash of clans but they don't want to be on the same village and they can't both be on app at the same time?

    hi, the app is not "shared", it works as if you bought the app twice with different accounts, only you paid it once. they should have 2 different villages since they're on 2 different devices.

  • My mac book gives electric shock through its entire body while being charged from AC out let. is there a solution to the problem? my other two friends are haveing the same problem who recently have purchased the same note books, its weird for APPLE

    My mac book gives electric shock through its entire body while being charged from AC out let. is there a solution to the problem? my other two friends are haveing the same problem who recently have purchased the same note books, its weird for APPLE products. Please give any solution.

    Is the MBP properly grounded?  Are you using the three prong plug?  If not, do so and your problems may disappear.  If not, do what SwankPeRFection suggests.
    Ciao.

  • Is it possible to have two SCCM instances for the same domain

    Hello - I'm the IT Project Manager for an organization that has a single domain-production.
    In here, we have an instance of SCCM 2012 setup. This instance is used to build packages, images, testing, validations, modifications etc. as well as for production roll outs. The primary issues we have with this is there is no separation between test and
    prod, also, there are several packages, task sequences etc causing confusion in determining which is a test package and which is prod.
    Setting up a test domain does not seem to be a viable option for us, at least for now.
    So, my question is, can we have another instance of SCCM in the same domain that we can restrict only for the sake of testing & validations and then use the original one to deploy the tested (gold) packets.
    Just a thought!! Does it make sense? Any challenges that we could face?
    Thanks in advance 
    Jagan Pantina
    JP

    Hi,
    Yes you can no problem, you should avoid having Boundary / Boundary Groups used for Site Assignment that overlap and make sure that PXE request to the test/dev environment is restricted to one test subnet to avoid co-existance issues.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • How can two independent DirectAccess servers be set up safely in the same domain?

    I've got a single-tier certificate authority running on a 2008 r2 domain controller with an expiring root certificate. I have a new 2012 r2 domain controller with a new single-tier certificate authority. I also have a DirectAccess server running on 2012
    server (two NICs, NAT, IP-HTTPS only). I'd like to get a new DirectAccess server set up running server 2012 r2 using the new CA for the various DirectAccess server and client computer certs. I can get the new environment working and flip machines from
    the existing implementation to the new implementation.
    I was previously told by a tech working one of my Microsoft support tickets that two independent DirectAccess servers can't run in the same domain. However, I posted a related question
    https://social.technet.microsoft.com/Forums/projectserver/en-US/ab53a314-91ea-4d40-afd5-6b8f62698547/2012-directaccess-and-expiring-certificate-authority?forum=winserverNIS and got a response indicating that two independent DirectAccess servers can run
    in the same domain. If I can carefully get a second server operational within the same domain, I can build a reg file to deploy to all machines prior to the cutover that will simulate the gpupdate for broken machines in the field, getting them connected so
    the policy can be properly pulled from a DC. Would anyone else be willing to confirm or elaborate on operating two independent DirectAccess servers in the same domain? What are the gotchas?

    Hi,
    Yes you can have 2 Da deployments in one domain.
    I have done this a number of times for customer when upgrading from UAG DA to 2012.
    Make sure you use different Group policies for the DA servers and Clients. make sure you target the client with only one GPO at a time. Also use different AD groups.
    You then change the GPO assignment to the clients and they will flip when the client does a gp update. I have done this for a site that had over 5000 clients and we didn't have one call about it.
    You can use DirectAccess Offline Domain Join for any broken machines.
    https://technet.microsoft.com/en-gb/library/jj574150.aspx
    Regards, Rmknight

Maybe you are looking for

  • UK Payroll - Local Government Teacher's Absence Scheme

    Hi Gurus, I am facing an issue with configuration of Local Government Teacher's Absence Scheme ( UK). Please let me know if anybody has worked on this. Thanks & Regards, Anupama

  • Please help me figure out what this kernel panic is about

    Computer keeps crashing. Went to genius bar, said it was sticky windows, deleted that, came home, still an issue. I can't decipher what all the Console gibberish means. Thu Apr 14 00:53:30 2011 panic(cpu 1 caller 0x55db30): "!pageList phys_addr"@/Sou

  • Synchronizaton of changes in SAP systems

    Hi! I have the following problem. I have two that are different, it means some tables are changed. Is there some transations and/or tool, that allows to track all the changes made in both systems comparing customer tables, reports, perhaps repository

  • Do not process BDC records that result in warnings

    Hi Experts, I have a BDC program to create absences.  When the result of the Call Transaction results in a warning, I do not want to process the record.  How can I do this BEFORE running the call transaction (since if I find out that there was a warn

  • How to call Java method from XSLT??

    Hi All, Jdev 11.1.1.3.0 I have a requirement to implement that, I have to call Java method from XSLT. Could anyone please suggest to implement that?? Thanks, Santosh M E