Skip to content

PKI Architecture

2-Tier PKI Architecture:

  • Root CA: Offline, Standalone, WORKGROUP
  • Issuing CA: Online, Enterprise, Domain-joined
┌─────────────────────┐
│ Root CA │
│ srv-rca-zrh-01 │
│ (Offline) │
│ WORKGROUP │
└──────────┬──────────┘
│ Signs
┌─────────────────────┐
│ Issuing CA │
│ srv-ica-zrh-01 │
│ (Online) │
│ corp.microsoftlab │
└──────────┬──────────┘
│ Issues
┌────────────────┼────────────────┐
│ │ │
┌──────▼──────┐ ┌──────▼──────┐ ┌──────▼──────┐
│ User │ │ Computer │ │ Web │
│ Certs │ │ Certs │ │ Server │
│ │ │ │ │ Certs │
└─────────────┘ └─────────────┘ └─────────────┘
VM IDHostnameIPRoleDomain
310srv-rca-zrh-0110.30.30.20Root CAWORKGROUP
311srv-ica-zrh-0110.30.30.21Issuing CAcorp.microsoftlab.ch
312srv-pki-zrh-0110.30.30.22PKI Web Repocorp.microsoftlab.ch
313srv-pki-zrh-0210.30.30.23PKI Web Repocorp.microsoftlab.ch
CAKey LengthHashValidityCRL Period
Root CARSA 4096SHA25620 Years12 Months
Issuing CARSA 3072SHA2565 Years7 Days
TypeURL
CRLhttp://pki.microsoftlab.ch/crl/
AIAhttp://pki.microsoftlab.ch/aia/