<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Active Directory Certificate Services Frequently Asked Questions - needs your help!</title><link>http://blogs.technet.com/b/pki/archive/2011/08/08/active-directory-certificate-services-frequently-asked-questions-needs-your-help.aspx</link><description>If you have commonly asked questions about certificate services or PKI that you think should be listed in the Active Directory Certificate Services Frequently Asked Questions (AD CS FAQ ) list, I encourage you to submit them to the TechNet Wiki posting</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Active Directory Certificate Services Frequently Asked Questions - needs your help!</title><link>http://blogs.technet.com/b/pki/archive/2011/08/08/active-directory-certificate-services-frequently-asked-questions-needs-your-help.aspx#3477083</link><pubDate>Wed, 25 Jan 2012 00:25:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3477083</guid><dc:creator>Kurt L Hudson MSFT</dc:creator><description>&lt;p&gt;Right now the ASKDS blog (&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/b/askds/"&gt;blogs.technet.com/.../askds&lt;/a&gt;) has good information about migrating certification authorities, especially the single to multiple tier migration.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/b/askds/archive/2011/11/11/friday-mail-sack-guest-reply-edition.aspx#camig"&gt;blogs.technet.com/.../friday-mail-sack-guest-reply-edition.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/b/askds/archive/2010/08/23/moving-your-organization-from-a-single-microsoft-ca-to-a-microsoft-recommended-pki.aspx"&gt;blogs.technet.com/.../moving-your-organization-from-a-single-microsoft-ca-to-a-microsoft-recommended-pki.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As for the renewing the issuing CA certificates, you just need to duplicate the Subordinate Certification Authority template, make your modifications, then Issue that template. Finally, use the option to Renew the CA Certificate in the Issuing CA Certification Authority console.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3477083" width="1" height="1"&gt;</description></item><item><title>re: Active Directory Certificate Services Frequently Asked Questions - needs your help!</title><link>http://blogs.technet.com/b/pki/archive/2011/08/08/active-directory-certificate-services-frequently-asked-questions-needs-your-help.aspx#3476842</link><pubDate>Mon, 23 Jan 2012 20:40:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3476842</guid><dc:creator>Tom L</dc:creator><description>&lt;p&gt;I spent a couple of months looking over documentation and other blog postings about upgrading the servers that run our PKI. &amp;nbsp;I specifically was looking to move our Enterprise Root CA to a Stand-Alone Root CA. &amp;nbsp;I pulled it off, but finding the documentation was not easy to do. &amp;nbsp;I now need to find a way to make our Issuing CA&amp;#39;s renew or acquire a subCA certificate that is longer than the riginal 2 years.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3476842" width="1" height="1"&gt;</description></item><item><title>re: Active Directory Certificate Services Frequently Asked Questions - needs your help!</title><link>http://blogs.technet.com/b/pki/archive/2011/08/08/active-directory-certificate-services-frequently-asked-questions-needs-your-help.aspx#3469842</link><pubDate>Thu, 08 Dec 2011 19:28:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3469842</guid><dc:creator>cr0m</dc:creator><description>&lt;p&gt;One thing I found myself doing before I even started my build was to go out and try and find horror stories. For example, some people just want to know... Are there any dangers to installing the Enterprise Issuing CA? Can it affect logins? Could it render the domain unusble. I think a good outline of potential risks and &amp;quot;gotchas&amp;quot; would be nice to read.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3469842" width="1" height="1"&gt;</description></item><item><title>re: Active Directory Certificate Services Frequently Asked Questions - needs your help!</title><link>http://blogs.technet.com/b/pki/archive/2011/08/08/active-directory-certificate-services-frequently-asked-questions-needs-your-help.aspx#3445915</link><pubDate>Tue, 09 Aug 2011 00:01:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3445915</guid><dc:creator>ADCS Answers ADCS FAQ</dc:creator><description>&lt;p&gt;You should also associate the AD CS FAQ with ADCS FAQ, ADCS Answers, and AD CS Answers.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://social.technet.microsoft.com/wiki/contents/articles/ad-cs-faq.aspx"&gt;social.technet.microsoft.com/.../ad-cs-faq.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3445915" width="1" height="1"&gt;</description></item></channel></rss>