Windows Server TechCenter > Windows Server Forums > Security > PKI for two different forests
Ask a questionAsk a question
 

AnswerPKI for two different forests

  • Monday, November 23, 2009 8:43 PMReppie Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    I am putting together PKI design for mostly internal clients but some will be on a DMZ.  I was looking to have an offline Root CA with two sub CAs, one in the internal forest and one in the DMZ forest.  I was going to use http and ldap CDPs.  Does it make sense to use http and ldap or just http since the subs are in different forests?  Is the only value with ldap CDP just if all clients are on the same internal forest?  Thank you.

Answers

  • Monday, November 23, 2009 9:26 PMVadims PodansMVPUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer

    If you want to use LDAP you will need to allow unauthenticated access to CDP folder in AD. also you may publish this point over internet without any problems.


    http://www.sysadmins.lv

All Replies

  • Monday, November 23, 2009 9:26 PMVadims PodansMVPUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer

    If you want to use LDAP you will need to allow unauthenticated access to CDP folder in AD. also you may publish this point over internet without any problems.


    http://www.sysadmins.lv