Forum Discussion
Ed Gallagher
Nov 21, 2018Brass Contributor
PKI Implementation
I'm implementing a two tier, offline Root CA, PKI for a small client with need for some "proper" security. Since it is a small business, I'm trying to reduce server count to keep maintenance and lice...
Petri Aalto
Nov 23, 2018Copper Contributor
IMO, I will keep Certificate servers always separately from other roles while you also have to think how to publish CRL list for example to Internet if there is a need. Secondly if something happens there is a risk how the renew all certificates in the client side where the users interuption shows a major thing if they cannot for example sign in to Network while the IEEE802.1x does not work.
Petri