hetty wrote: From watching the CBT Nuggets, its suggested that the server is taken offline completely, whats to stop someone from starting the service up again or stealing the hard drive?. At the very least you could be running the root CA from a VM and securely encrypt it in a TrueCrypt volume or similar. And place that hard drive or dvd in the company safe. I havent read the book yet but im sure its something similar in operation.
donald7862003 wrote: Yeah but it sounds like a waste of hard drive. But ok.............
dynamik wrote: edit: Donald, this is recommended for large organizations. Having a CA compromised for thousands of users would be detrimental. A few thousand dollar server sitting in a locked closet is a small price to pay for that security. This isn't a recommended solution for a 25-person business.