High availability for AD CS

bizcntradmin 191 Reputation points
2020-10-29T14:57:07.663+00:00

We have a two tier PKI (both VM) what is the best solution for HA. In case the servers goes down?

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
526 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-10-30T00:45:17.333+00:00

    Hi,

    Just from the High availability for the PKI, using multiple CAs is good way to ensure that your infrastructure can support enterprise scalability.
    Such as one offline Root CA,with 2 issue CA in your environment.
    Also, one important thing, backup CA, to ensure that the server can be restored from the backup when it is down.
    For your reference:
    https://social.technet.microsoft.com/wiki/contents/articles/7421.active-directory-certificate-services-ad-cs-public-key-infrastructure-pki-design-guide.aspx#Plan_for_CA_Capacity_Performance_and_Scalability

    Best Regards,

    0 comments No comments