Scenario:
- We have two departments within IT; Say
Department-OLDandDepartment-NEW. - A single internal PKI environment exists and a root CA (singular) is trusted by All
endpoints.
Problem:
Department-New, in the same network, is doing a lot of new development. They need to issue certificates to all their systems and applications, but we don't want the remainder of the organization (Department-OLD and endpoints) to trust the certificates used by Department-NEW.
How can this be accomplished?
- I want "Department-New" to not want "Department-Old" to come to "Department-Old" to issue exception based certs for systems that need to now be trusted
- I'd not install the root CA for "Department-New" on hosts in "Department-Old" because then they'd trust certs (of "Department-New"
– Xorprime Jul 10 '15 at 10:35