Guest youngny Posted November 20, 2007 Posted November 20, 2007 Hi, In my current environment I've 3DC running windows 2003 SP1, one dc is running Certificate authority and it is also running IAS. My goal is to remove CA from the DC and install it on a member server and remove IIS from the DCs to improve the security of the DCs. We are using IAS for the wireless client authentication. The current certificate which is installed on the clients will expire next year in April. Are there any guidelines to remove CA from DC to a member server. Should I leave IAS on the DC or move it to a member server. I've read it is better to leave IAS on a DC for performence reasons. Any help will be appreciated. Thanks
Recommended Posts