You administer an Active Directory Domain Services environment. There are no certification authorities (CAs) in the environment.You plan to implement a two-tier CA hierarchy with an offline root CA.You need to ensure that the issuing CA is not used to create additional subordinate CAs.What should you do?
A. In the CAPolicy.inf file for the issuing CA, enter the following constraint: PathLength=1
B. In the CAPolicy.inf file for the root CA, enter the following constraint: PathLength=1
C. In the CAPolicy.inf file for the root CA, enter the following constraint: PathLength=2
D. In the CAPolicy.inf file for the issuing CA, enter the following constraint: PathLength=2
You administer an Active Directory Domain Services environment. There are no certification authorities (CAs) in the envi
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
You administer an Active Directory Domain Services environment. There are no certification authorities (CAs) in the envi
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!