AD CS components
AD CS is a collection of role services, and they can be used to design the PKI for your organization. Let's look into each of these role services and their capabilities.
The CA
CA role service is responsible for issuing, storing, managing, and revoking certificates. The PKI setup can have multiple CAs. There are two main types of CAs:
- The root CA: The root CA is the most trusted CA in the PKI setup. A compromised root CA will compromise an entire PKI. Therefore, the security of the root CA is crucial. Best practice is to bring the root CA online only when required. By considering the security and hierarchy of the PKI, it is recommended to use the root CA only to issue certificates to subordinate CAs.
- Subordinate CAs: In PKI, subordinate CAs are responsible for issuing, storing, managing, and revoking certificates for users, devices, or services. Once a CA receives a certificate request, it will process it and issue the certificate. A...