New Certification Authority - PKI: chain with key lenght at 4096 bit, impacts and Hybrid Chain.

49885604 215 Reputation points
2024-06-10T17:07:59.2766667+00:00

Hi everyone,

I have to create a new PKI and I would like to know if I can create a 4096 key for the RootCA certificate, for the Issuing CA and for all the Certification Authority services (WebEnrollment, NDES, OCSP etc...). Obviously I would also like to create 4096 templates and certificates, are there best practices for the impacts on clients, servers, devices and platforms with a completely 4096 chain?

Would it be possible to create a chain at 4096 up to the IssuingCA and then create template\certificates at 2048?

The Operating System I would like to use is Windows Server 2022.

Thanks in advance,

Alessio.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.