Certificate Services

  • Thread starter Thread starter Justin Miller
  • Start date Start date
J

Justin Miller

I am setting up Cert Services in Win2K to issue my certs
for all my intranet sites. Just wondering if it's
possible for me to setup cert services to be subordinate
to some other trusted root CA (i.e. Verisign) so that I
don't have to add my private CA to the browser list? If
this is possible, how do I request this from the CA? I
have asked the nice people at GEOTRUST but I get no
response.
 
Yes it is possible, however if you are in a domain and use an Enterprise
Root CA, the Root CA certificate will come down automatically.


--Shawn
This posting is provided "AS IS" with no warranties and confers no rights.
 
it's not in a domain, just a stand-alone certificate
server that i want to issue certs with. geotrust just
emailed me back telling me this isn't possible. are they
correct?
 
I can't comment on whether or not you can subordinate under geotrust,
however I do know it is possible for a Microsoft CA to subordinate under a
different company's CA, I cannot comment on the actual companies.

You can push a Standalone root CA cert down by group policy.


--Shawn
This posting is provided "AS IS" with no warranties and confers no rights.
 
Technically it is possible - Geotrust would just sign your subordinate CA
request with their root. Verisign and Baltimore both offer this service.
 
Back
Top