Hello,
We are currently on Windows 2003 Domain & Forest Functional Level. Our Root CA is also currently on Windows 2003 DC.
If we have to setup a new Root/Issuing CA ( not exporting the current 2003 CA cert) on Windows 2012 R2 servers, is it then mandatory to first upgrade Domain & Forest levels to 2012 R2 ? Can we have a PKI infrastructure with Enterprise CA's on a Windows 2012 Platform but the Domain/Forest levels still on 2003 level ? i understand it will be good to have everything on 2012 R2 , but can a mix of 2003 domain level and 2012 CA work ?