Jump to content

Issuing CA - Common Name?


Recommended Posts

Guest BillL
Posted

Hi,

 

Our MS PKI environment currently includes 1 offline root CA and 1

online enterprise issuing CA. We want to add a 2nd enterprise issuing

CA for redundancy. I believe that this 2nd issuing CA should have a

different Common Name than the 1st issuing CA. It's not clear from

the documentation that I have looked at. Is this a correct

assumption?

 

Thanks,

Bill

  • Replies 3
  • Created
  • Last Reply
Guest Paul Adare
Posted

On Mon, 23 Jun 2008 13:44:42 -0700 (PDT), BillL wrote:

<span style="color:blue">

> Our MS PKI environment currently includes 1 offline root CA and 1

> online enterprise issuing CA. We want to add a 2nd enterprise issuing

> CA for redundancy. I believe that this 2nd issuing CA should have a

> different Common Name than the 1st issuing CA. It's not clear from

> the documentation that I have looked at. Is this a correct

> assumption?</span>

 

It _must_ have a different common name.

 

--

Paul Adare

http://www.identit.ca

Programmers do it bit by bit.

Guest BillL
Posted

On Jun 23, 5:11 pm, Paul Adare <pkad...@gmail.com> wrote:<span style="color:blue">

> On Mon, 23 Jun 2008 13:44:42 -0700 (PDT), BillL wrote:<span style="color:green">

> > Our MS PKI environment currently includes 1 offline root CA and 1

> > online enterprise issuing CA.  We want to add a 2nd enterprise issuing

> > CA for redundancy.  I believe that this 2nd issuing CA should have a

> > different Common Name than the 1st issuing CA.  It's not clear from

> > the documentation that I have looked at.   Is this a correct

> > assumption?</span>

>

> It _must_ have a different common name.

>

> --

> Paul Adarehttp://www.identit.ca

> Programmers do it bit by bit.</span>

 

Thanks Paul.

  • 3 weeks later...
Posted

Hi

the reason why it must have a different common name is because being an

enterprise CA it publishes certain information to Active Directory. If 2

enterprise CAs had the same common name then there would be 2 machines trying

to publish the same data.

The easiest way to find the data I am talking about it to start 'Active

Directory Sites and Services'

Click to high-light Active Directory Sites and Services[FQDN of domain

controller]

Click View > Show Services Node

Now expand Services

Expand 'Public Key Services'

Look in the AIA, CDP, Enrollment Services folders for Enterprise CA info.

 

"BillL" wrote:

<span style="color:blue">

> On Jun 23, 5:11 pm, Paul Adare <pkad...@gmail.com> wrote:<span style="color:green">

> > On Mon, 23 Jun 2008 13:44:42 -0700 (PDT), BillL wrote:<span style="color:darkred">

> > > Our MS PKI environment currently includes 1 offline root CA and 1

> > > online enterprise issuing CA. We want to add a 2nd enterprise issuing

> > > CA for redundancy. I believe that this 2nd issuing CA should have a

> > > different Common Name than the 1st issuing CA. It's not clear from

> > > the documentation that I have looked at. Is this a correct

> > > assumption?</span>

> >

> > It _must_ have a different common name.

> >

> > --

> > Paul Adarehttp://www.identit.ca

> > Programmers do it bit by bit.</span>

>

> Thanks Paul.

> </span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...