What happen if a Windows server CA lost his trust relationship with DC?

Daisy Zhou 18,701 Reputation points Microsoft Vendor
2020-07-15T06:49:52.897+00:00

What happen if a Windows server with CA role lost his trust relationship with DC?
The server is still up but I'm just curious what is the impact because I heard it can be installed on a stand alone server too.

Source link:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/bd15b214-087f-466a-b0fc-45a42633fda7/what-happen-if-a-windows-server-ca-lost-his-trust-relationship-with-dc?forum=winserverManagement

Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
420 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2020-07-15T06:53:00.96+00:00

    Hello,

    Thank you so much for your feedback.

    As Dave mentioned, the CA server should be on a member server in a domain environment. Usually there will be Single Tier PKI Hierarchy Deployment and Two Tier PKI Hierarchy Deployment.

    There are four computers involved in this single-tier PKI hierarchy as shown below. The CA server is on a member server.
    12397-15.png
    There are five computers involved in this two-tier PKI hierarchy lab as shown below.

    In this two-tier PKI hierarchy, Standalone Offline Root CA will be configured. The standalone offline root CA should not be installed in the domain, so it is on a stand alone server.
    12278-16.png
    We are wondering whether you have any doubt about standalone offline root CA. For more information, please refer to:

    ADCS Step by Step Guide: Single Tier PKI Hierarchy Deployment
    https://social.technet.microsoft.com/wiki/contents/articles/11750.adcs-step-by-step-guide-single-tier-pki-hierarchy-deployment.aspx

    AD CS Step by Step Guide: Two Tier PKI Hierarchy Deployment
    https://social.technet.microsoft.com/wiki/contents/articles/15037.ad-cs-step-by-step-guide-two-tier-pki-hierarchy-deployment.aspx

    Hope the information is helpful. For any question, please feel free to contact us.

    0 comments No comments

0 additional answers

Sort by: Most helpful