积极答复者
为什么不建议将证书服务安装在域控服务器上?

问题
答案
-
Depending on your Active Directory Certificate Services deployment scenario, you might encounter the following situations:
- After you install a Certificate Authority on a Domain Controller, the Domain Controller can no longer be renamed or demoted.
- Switching to an Enterprise Root Authority (for v3 templates) from a Standard Root Authority requires reinstallation of Windows Server. Reinstallation of Domain Controllers is not to be taken lightly.
- Upgrading the Certificate Authority requires upgrading the Active Directory Domain Controller and thus Active Directory Schema.
- You cannot deploy an offline root Certificate Authority on a Domain Controller (and keep it offline for a period longer than the default tombstone lifetime)
- It is unadvisable to deploy an Internet-facing Certificate Authority of Online Responder on a Domain Controller. This is a serious security risk.
- 已标记为答案 Guo Ying Hui 2013年4月12日 1:32
全部回复
-
Depending on your Active Directory Certificate Services deployment scenario, you might encounter the following situations:
- After you install a Certificate Authority on a Domain Controller, the Domain Controller can no longer be renamed or demoted.
- Switching to an Enterprise Root Authority (for v3 templates) from a Standard Root Authority requires reinstallation of Windows Server. Reinstallation of Domain Controllers is not to be taken lightly.
- Upgrading the Certificate Authority requires upgrading the Active Directory Domain Controller and thus Active Directory Schema.
- You cannot deploy an offline root Certificate Authority on a Domain Controller (and keep it offline for a period longer than the default tombstone lifetime)
- It is unadvisable to deploy an Internet-facing Certificate Authority of Online Responder on a Domain Controller. This is a serious security risk.
- 已标记为答案 Guo Ying Hui 2013年4月12日 1:32