1. Should (or can) the offline root be a stand alone root CA, or should I
install it as an enterprise offline root CA?
2. If I can (and do) install it as an enterprise offline root CA would it be
on a member server or a Domain controller? (if on a DC how will the domain
cope with a DC being offline?)
3. Can the offline CA be installed on a Virtual Server?
--
Chris
--
Chris
> 1. Should (or can) the offline root be a stand alone root CA, or should I
> install it as an enterprise offline root CA?
The root CA be used installed as either SA or Ent. But it is prefered to be
a standalone.
> 2. If I can (and do) install it as an enterprise offline root CA would it be
> on a member server or a Domain controller? (if on a DC how will the domain
> cope with a DC being offline?)
It is never recommended to be installed on a DC, except in a testing ot
training environment. If you bring down your DC, the AD replication will
experience problem with other DCs in the replication ring. So don't ever do
it.
> 3. Can the offline CA be installed on a Virtual Server?
Yes, no problem at all, as long as the guest OS is able to communicate with
the network.
HTH.
> pls see in-line.
>
>
> > 1. Should (or can) the offline root be a stand alone root CA, or should I
> > install it as an enterprise offline root CA?
>
> The root CA be used installed as either SA or Ent. But it is prefered to be
> a standalone.
By definition an offline root must be standalone. Your can't have an
Enterprise root offline.
>
>
> > 2. If I can (and do) install it as an enterprise offline root CA would it be
> > on a member server or a Domain controller? (if on a DC how will the domain
> > cope with a DC being offline?)
>
> It is never recommended to be installed on a DC, except in a testing ot
> training environment. If you bring down your DC, the AD replication will
> experience problem with other DCs in the replication ring. So don't ever do
> it.
>
> > 3. Can the offline CA be installed on a Virtual Server?
>
> Yes, no problem at all, as long as the guest OS is able to communicate with
> the network.
This won't be supported until R2 of Virtual Server is released.
>
> HTH.
>
>
--
Paul Adare
MVP - Windows - Virtual Machine
http://www.identit.ca/blogs/paul/
"The English language, complete with irony, satire, and sarcasm, has
survived for centuries without smileys. Only the new crop of modern
computer geeks finds it impossible to detect a joke that is not clearly
labeled as such."
Ray Shea