Is role separation supported?
Windows 2003 and Windows 2008 CAs support the Common Criteria role separation. Several user roles exist to increase the security of the CA. The following roles exist: CA Administrator – Manages the CA and is allowed to configure the certificate templates. CA Manager – Authorizes certificate requests and revokes certificates. The CA manager is allowed to recover private keys. Auditor – Analyses the security event log. Backup Operator – Performs the backup of the CA database, configuration and keys.