Certificates - Cross Certificate


we have 2003 certificate server. wish add windows 2012 certificate server same domain preserve windows 2003 server old existing certificates not compatible new 2012 features.  the 2003 no longer able push out new certificates, 2012 server able this. each server has separate rootca independent of each other. long term goal retire 2003 server when xp machines out. 

is necessary create cross certification cert 2003 , 2012 servers talk each other? since 2003 server not doing servicing existing certs, cross certificate necessary?


it depends on several factors. example, if can deploy new root ca certificate clients enough (you can pause new pki launch until clients receive new ca certificate), don't need cross-certification. however, if need launch new pki immediately, have cross-certify new pki.

my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
check out new: powershell fciv tool.



Windows Server  >  Security



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client