PKI - Best practices for High Availability or Balancing of CRL and NDES services

49885604 235 Reputation points
2023-12-12T16:35:45.9566667+00:00

Hi all,
In order to configure the Certification Authority services in High Availability or Balancing I need to know:

-What is recommended for the CRL in terms of HA or Balancing configurations? Could I add a further CRL server used for certificate revocation? (for example: i could create a new DNS record and new CDP record for all IssuingCA)

-What is recommended for NDES in terms of HA or Balancing configurations? It seems that only one Issuing CA can be targeted for the NDES service. Is it correct?

Can you help me with Microsoft Best Practices dedicated to these specific topics?

Kind regards,

Alessio.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Thameur-BOURBITA 36,506 Reputation points Moderator
    2023-12-12T21:54:30.15+00:00

    Hi @49885604

    -What is recommended for the CRL in terms of HA or Balancing configurations? Could I add a further CRL server used for certificate revocation? (for example: i could create a new DNS record and new CDP record for all IssuingCA)

    It's recommended to publish crl on a web server http. This server should be high available. Regarding the DNS record , I recommend to create a alias in order to simplyfy server migration when you need to upgrade OS for example.

    You can alse use multiple web server to ensure the high availabilityL.

    You can refer t the follow link to get more details about CRL best practice:

    PKI Best Practices

    -What is recommended for NDES in terms of HA or Balancing configurations? It seems that only one Issuing CA can be targeted for the NDES service. Is it correct?

    Can you help me with Microsoft Best Practices dedicated to these specific topics?

    I invite you to read the following link :

    NDES Security Best Practices


    Please don't forget to accept helpful answer


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.