TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Microsoft CA Reading Material

1 点作者 lax4ever将近 2 年前
Does HN have some recommended readings for Microsoft's CA role, Certificates, and PKI? My company is preparing to replacing our domain controllers (hardware replacement and going from 2012 R2 to Server 2022) and one of them has our local CA. It's not used for much right now (DC authentication, Kerberos, and Exchange), but I am trying to decide if it will be simpler to migrate or just start a new CA.

1 comment

ailurooo将近 2 年前
<a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B010EUQPPY?psc=1" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B010EUQPPY?psc=1</a> I started with this book. But honestly there&#x27;s just alot of reading to do to setup the root cert correctly and supportable going forward. Like the default root cert has too low of ... numbers..There&#x27;s stuff you want to customize when setting up the root cert that MS doesn&#x27;t specify and it&#x27;s kinda a major nightmare, i recommend doing a lab environment and testing.<p>Likely people who install a CA on a DC don&#x27;t know admining and therefore i would recommend setting up a new cert. And&#x2F;or ask why you&#x27;re even using a certificate authority in the first place. As kerberos authentication between windows is really solid even without a cert authority.
评论 #36604908 未加载