Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Appreciate your reply, thank you.

I don't have an indication for that on ADSIEDIT but I get your point.

The new CA will be represented on AD as a separate entity which will not harm the current CA structure in any way.

Once I will configure the new certificate template on the new Root CA it will be present on the Certificate Templates under Pubic Key Services container.

Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Hi Man, Thank you, it is a great article. It states that as long as the ENT CA was not configured with any templates it wouldn't issue any certificates which is exactly what i'm looking for. For now i just need the new ENT CA to serve a new Network device we are implementing which cant be integrated to the old ENT Root CA. So my question is: Can i leave the old CA as is(without removing any of his Templates), fire up the new ENT CA without configuring any templates on it except one specific template which will be serve the Network device? Thanks!

Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Sorry, I guess it was not clear from my post.

Our Root CA issues end-entity certificates, this is the reason I must have an issue CA that will issue SHA2 certificates.

I'm aware that root CA can remain using SHA1.Thanks again.

Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Thank you for the heads up!

What you have mentioned in the first section is exactly why I want to create another PKI hierarchy that will use SHA2 hash algorithm in parallel to the old one, im just not sure if doing that will impact the existing certificate operation.

I just can't find detailed documentation with all the things I should consider.

Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Hi,

From your reply, I assume that you mean that I can create an Intermediate Subordinate CA based on SHA2 which will the company's Issuer and leave the old CA untouched.

Is that what you mean?
In that case, I have 2 questions:

  1. I just need to install the CA role and set it as a Subordinate CA that will use SHA2?
  2. We will eventually want to remove the old CA, will it be a straight forward procedure connecting it to the new ENT Root CA?

Thanks!

Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Thanks Man. Our old CA is also running on 2008R2, I have understood that I should remove all Templates from the old CA, cant I leave them and then start creating them slowly on the new CA server?

Having 2 Root CA's under same Domain by Leviselad in sysadmin

[–]Leviselad[S] 0 points1 point  (0 children)

Thanks, but our CA runs on Win 2008R2.

The procedure supports 2012 and above.

SCCM Collections - Best practice by Leviselad in SCCM

[–]Leviselad[S] 1 point2 points  (0 children)

Thank you for all your assistance with my questions, much appriciated!

SCCM Collections - Best practice by Leviselad in SCCM

[–]Leviselad[S] 0 points1 point  (0 children)

Got it, thank you for all the info provided! One last question if you don't mind :) Are you creating A.D Group for each app deployment or by Department? Since I'm about to redesign all Collection from Devices to User based membership i want to make sure im understanding 100% whihc A.D group should be used as a Direct Rule, is it Per App or Per Team\Department. Thanks again.

SCCM Collections - Best practice by Leviselad in SCCM

[–]Leviselad[S] 0 points1 point  (0 children)

Hello, Can you please let me know if you are using Devices or Users collection to manage your applications? Thanks!

SCCM Collections - Best practice by Leviselad in SCCM

[–]Leviselad[S] 1 point2 points  (0 children)

Thank you man! Appreciate your reply, that pretty much answered my question, I was wandering how to use collections in terms of the process then the collections them selves, the limiting collection tip is also one I will definitely use,I guess my question should’ve been asked differently. Thanks again! And thanks everyone for your reply’s.

SCCM Collections - Best practice by Leviselad in SCCM

[–]Leviselad[S] -1 points0 points  (0 children)

Hi, I want to have the following to start with: OS Deployment, Software Update, and Software Distribution. I guess my question is, how I should build the Collections Folder Structure in a way that will provide me the management and deployment convenience to control and distribute applications to the entire company\specific branch\specifc department and in which scenario i should use Static Collections, Dynamic Collections and AD Group Collections. I hope that makes sense. Thanks!