2 Certificate Authoritiy servers on a single network with different certificates.
hi all,
i 'inherited' network on , and finding lot of problems can't figure out , hope here can me.
to give basic idea of network, have 85 users , 9 servers of 2 of them dc's both running windows 2008. have exchange 2003 running on windows 2003.
now problem this. 1 of dcs certificate authority on server , need format because not stable @ moment. exchange server happens certificate authority too. when checked certificates have both have totally different certificates , not 1 replicated.
now question is possible transfer certificates both servers single server , ca network? worth having 2 ca's on single network? work fail-over each other or anything?
another thing, of certificates have expired, best possible way issue renewal?
thanks in advance.
if have centralized administration think have, there no reason have more single internal ca.
also consider may completelly uninstall , discard old cas - there prevent installing new ca , reissuing certificates? use several server certificates anyway. because "move" operation not possible in simple , supported way.
ondrej.
Windows Server > Security
Comments
Post a Comment