Jump to content

Hello everyone. I run my own Certificate Authority a 2 tier PKI with 2 off line 2 Root CAs (RSA and ECC). The Root CAs and the Subordinate CAs are dedicated servers running at a datacenter. The question is. Who gets audited? Because the servers are not located within my on-premise network..

 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 32 GB (4x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitor: 24" Acer S240HLBID | OS: Win 11 Pro.

 

Home Lab:  Lenovo ThinkCenter M82 Hyper-V Server 2022 | Dell OptiPlex 9020 Hyper-V Server 2022 | TP-LINK TL-SG108E | Cisco Catalyst C2960CG 8 Port Switch | HP MicroServer G8 SCCM Server | 2x Dell PowerEdge R630 Hyper-V Server 2022

 

 

Link to comment
https://linustechtips.com/topic/1012076-certificate-authority-audit/
Share on other sites

Link to post
Share on other sites

If you're getting a CA Audit - they'll be looking at you as a CA so will be auditing you not the data center. However, if the DC you are using is insecure (failure to adequately protect the infrastructure) - this may be flagged up during the audit.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×