Lifecycle
Here you will find details on the lifecycle of class E certificates (Windows PKI).
The certificate request is implicitly included in the order for the creation or modification of an account and/or for the inclusion of a computer system in a Windows Active Directory domain of the Federal Administration (INTRA and FDFA forests).
The functionality of the Microsoft Enterprise PKI is used as the basis for the issuance process, which provides the option of automatic registration and issuance (auto-enrolment). Based on permissions on the defined certificate templates, as well as group memberships and GPOs (group policy objects), it is specified in detail which users and computer systems are to receive a given certificate
Only the web server SSL certificates and ConfigMgr OS deployment must be requested individually by the server administrator by means of an electronic request. This is due to the attribution of names.
The “SwissGovernment-E-Intra01 for the INTRA forest” and “SwissGovernment-E-EDA01 for the FDFA forest” generate, validate, publish and manage the certificates of certificate holders's.
The issuance and management of class E (Windows PKI) certificates are based on a two-tier hierarchical infrastructure.
- Level 1, “RootCA SwissGovernment-E-Root01”, validates level 2, “SwissGovernment-E-Intra01 for the INTRA forest” and “SwissGovernment-E-EDA01 for the EDA forest”.