Setting up a CA Hierarchy is too hard
Man Certificate Authorities are just hard. And the documentation is lengthy and cryptic. Why hasn't anyone written it up in a simpler form?
In the next few posts I'll show you in easy language how to set up a root CA and an Enterprise Subordinate CA, including support for the AIA extension, the Certificate Revocation List and a CRL Distribution Point.
Here's our root certificate and the Enterprise CA Certificates (#1 and #2) so that you can see the result.