Planning PKI
By now, we understand what PKI is and how it works. You have also learned about AD CS components and their capabilities. The next thing is to plan the deployment of the PKI. In this section, we will look into the things we need to consider during the PKI planning process.
Internal or public CAs
AD CS is not just a role that we can install on a server and leave to run. It requires knowledge to set up and operate. It needs to be maintained like any other IT system. We also need to consider high availability. All this comes at a cost. Public CA certificates need to be purchased through a service provider. Each provider has many different types of certificates with different price ranges. It is important to evaluate these associated costs against your company's requirements. If the company is looking for a few web service certificates, there is no point in maintaining a few servers internally just for that. If a public CA can offer the same thing for $15, it...