Windows Server TechCenter > Windows Server Forums > Security > When an Enterprise subordinate CA is offline
Ask a questionAsk a question
 

AnswerWhen an Enterprise subordinate CA is offline

  • Friday, November 06, 2009 4:38 AMSNeo Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    Hi, I'm just trying to understand this:

    In a two-tier PKI setup with a standalone root CA and two Enterprise subordinate CAs, will the certificates issued by a subordinate CA be valid if the issuing CA becomes unavailable?

    cheers,
    soon

Answers

  • Friday, November 06, 2009 5:58 AMBrian Komar [MVP]MVPUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Only if you have created measures to re-sign the previous CRL. Once the CRL of a failed CA expires, applications that perform CRL checking will fail.
    Brian
    • Marked As Answer bySNeo Monday, November 09, 2009 1:38 AM
    •  

All Replies