Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
When network administrators hear that their organization is going to deploy a Windows Server 2008 public key infrastructure (PKI), several questions typically come to mind:
Do I have to upgrade all domain controllers in my forest to Windows Server 2008? The answer is no. A Windows Server 2008 PKI is not dependent upon Windows Server 2008 domain controllers. You can deploy a Windows Server 2008 PKI in a Microsoft Windows 2000 or Windows Server 2003 Active Directory directory service environment.
Do I have to upgrade my domain functional level or forest functional level to Windows Server 2008? No again. A Windows Server 2008 PKI has no requirements for domain or forest functional levels.
What do I have to do to deploy a Windows Server 2008 PKI? This chapter will describe the actions you must take to prepare Active Directory Domain Services (AD DS) to deploy a Windows Server 2008 PKI.