AD CS: Deploying Cross-forest Certificate Enrollment

Rich Marder 1 Reputation point
2020-08-01T11:39:35.533+00:00

With reference to the article https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ff955845(v=ws.10) can somebody please clarify if I already have a Enterprise CA in an Account Forest can I establish a 'Cross Forest Enrollment' with a Resource Forest and maintain the Enterprise CA in the Account Forest or do I have to consolidate this Account Forest CA into the Resource Forest?

The reason I am asking is because we have a small user base in Account Forest and want to integrate these into an AOVPN solution in the Resource Forest.

Thanks in advance for any advise/help.

Rich

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,106 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,832 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,721 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2020-08-03T04:58:15.687+00:00

    Hi,
    Based on my research, from the management, both the methods you mentioned can be considered.
    Since you have only a small user base in Account Forest,for easier management, you can consolidate this Account Forest CA into the Resource Forest .
    Not familiar with the AOVPN solution, you may combine various factors and choose an appropriate method.

    Following link for your refrence:
    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ff955842(v=ws.10)?redirectedfrom=MSDN

    Fan