Planning PKI
By now, we understand what PKI is and how it works. You also learned about AD CS components and their capabilities. The next thing is to plan the deployment of PKI. In this section, we will look into things we need to consider during the PKI planning process.
Internal or public CAs
AD CS is not just a role that we can install on a server and leave it to run. It needs resources to run the role services. It needs knowledge to set up and operate it. It needs to be maintained as any other IT system. It also needs solutions for backup and high availability. All these come with a cost. On the other hand, public CA certificates need to be purchased through a service provider. Each provider has many different types of certificates with different price ranges. It is important to evaluate these associated costs against the company requirements. If its regarding a few web service certificates, there is no point to maintain few servers internally just for that. If a public CA can offer same...