1 00:00:06,720 --> 00:00:16,320 You can use a subordinate C to implement policy restrictions for PGI and to issue certificates to clients 2 00:00:16,860 --> 00:00:20,360 after and stolen a rootsy C for the organization. 3 00:00:20,400 --> 00:00:29,610 You can install one or more subordinate seats when you use a subordinate C to issue certificates to 4 00:00:29,610 --> 00:00:34,890 users or computers that have an account in an HDD environment. 5 00:00:35,010 --> 00:00:44,130 You can install the subordinate C as an enterprise C then you can use the data from the client accounts 6 00:00:44,430 --> 00:00:55,600 in ADT has to issue and manage certificates and to published certificates to HDD to complete this procedure. 7 00:00:55,620 --> 00:01:04,530 However you must be a member of the local administrators group or have equivalent permissions If the 8 00:01:04,530 --> 00:01:08,360 subordinate C is an enterprise c. 9 00:01:08,370 --> 00:01:18,110 You also need to be a member of domain Edmonds group or have equal and permissions from a security perspective. 10 00:01:18,170 --> 00:01:26,450 I recommended scenario would be to have a no fly zone stand alone route C and an enterprise subordinate 11 00:01:26,460 --> 00:01:36,150 C and subordinate C usually deploys to achieve some of the following functionalities usage. 12 00:01:36,150 --> 00:01:45,870 You can issue certificates for a number of purposes such as secure multipurpose Internet mail extensions 13 00:01:46,750 --> 00:01:49,970 EHR fast or remote access. 14 00:01:50,040 --> 00:02:00,590 This issue and policy for these different uses might be distinct and separation provides the basis for 15 00:02:00,600 --> 00:02:03,960 administrating these policies. 16 00:02:04,810 --> 00:02:08,940 And all that functionality is organizational divisions. 17 00:02:09,160 --> 00:02:17,890 You might have different policies for issuing certificates that depend on the entities role in the organization. 18 00:02:17,890 --> 00:02:27,260 You can create subordinate seas to separate and administer these policies and other functionality as 19 00:02:27,720 --> 00:02:29,720 geographic divisions. 20 00:02:29,730 --> 00:02:38,110 Organization often have in entities at multiple physical sites limited network connectivity between 21 00:02:38,230 --> 00:02:50,160 these sites might necessitate individual subordinates he for manager or role site and other functionalities. 22 00:02:50,160 --> 00:02:51,570 Load balancing. 23 00:02:52,110 --> 00:03:00,600 If you use your API to issue and manage a large number of certificates and have only one seat you can 24 00:03:00,600 --> 00:03:11,360 result in considerable network load that the single C uses you then multiple subordinate seems to issue 25 00:03:11,360 --> 00:03:13,670 the same kind of certificates. 26 00:03:13,810 --> 00:03:20,050 Do white the network load between CS and the last functionality. 27 00:03:20,150 --> 00:03:30,160 For now is back up and fault tolerance multiple CS increase the possibility that your network has operational 28 00:03:30,340 --> 00:03:34,480 CS available to respond to user requests.