0

I want to deploy a new PKI infrastructure on a domain that has several subdomains and trusted domains. I would like to be able to delegate the administration between several administrators corresponding to the subdomains and trusted domains. Would the appropriate implementation for this environment be a root CA (enterprise) and then a subordinate CA for each domain? Would it be necessary a server for each subordinate CA?

In the case of an implementation with only one root CA (without subordinate CA), would it be possible to give permissions to local administrators so that they can only issue certificates for their domains?

Santyuste
  • 19
  • 1

0 Answers0