configuring active directory certificate services

60
Configuring Active Configuring Active Directory Certificate Directory Certificate Services Services Lesson 13

Upload: peers

Post on 14-Jan-2016

56 views

Category:

Documents


2 download

DESCRIPTION

Configuring Active Directory Certificate Services. Lesson 13. Skills Matrix. Skills Matrix. Installing Active Directory Certificate Services. Log on to the CA member server as the default administrator of the lucernepublishing.com domain. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Configuring Active Directory Certificate Services

Configuring Active Configuring Active Directory Certificate Directory Certificate

ServicesServicesLesson 13

Page 2: Configuring Active Directory Certificate Services

Skills MatrixSkills Matrix

Technology Skill Objective Domain Objective #

Installing Active Directory Certificate Services

Install Active Directory Certificate Services

6.1

Configuring CA Server Settings

Configure CA server settings

6.2

Configuring Certificate Templates

Manage certificate templates

6.3

Page 3: Configuring Active Directory Certificate Services

Skills MatrixSkills Matrix

Technology Skill Objective Domain Objective #

Managing Certificate Enrollments

Manage enrollments 6.4

Configuring Certificate Revocation

Manage certificate revocations

6.5

Page 4: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Installing Active Directory Certificate Services

Log on to the CA member server as the default administrator of the lucernepublishing.com domain.

If the Server Manager console does not appear automatically, click the Start button.

Select Server Manager from the Start menu.

Page 5: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Installing Active Directory Certificate Services (cont.)

Expand the Server Manager console to full screen, if necessary.

In the left pane, click the Roles node.

In the right pane, click Add Role.

Click Next to bypass the initial welcome screen.

Page 6: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Installing Active Directory Certificate Services (cont.)

Place a checkmark next to Active Directory Certificate Services, and click Next.

Read the information presented, and click Next.

Place a checkmark next to Certification Authority, and click Next.

Select the Enterprise radio button, and click Next.

Page 7: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Installing Active Directory Certificate Services (cont.)

Select the Root CA type radio button, and click Next.

Select the Create a new private key radio button, and click Next.

Accept the default values, and click Next.

Accept the default value, and click Next.

Page 8: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Installing Active Directory Certificate Services (cont.)

Accept the default value of 5 years, and click Next.

Accept the default values, and click Next.

Verify that your selections are correct, and click Install.

Click Close to complete the installation.

Page 9: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation

Part A: Install the Online Responder

Log on to CA as the default administrator of the lucernepublishing.com domain.

Click the Start button, and then select Server Manager.

Drill down to RolesActive Directory Certificate Services.

Page 10: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Right-click Active Directory Certificate Services, and select Add Role Services.

Place a checkmark next to Online Responder.

Click Add Required Role Services, and then click Next to continue.

Read the informational message concerning the installation of the Web Server role, and click Next.

Page 11: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Accept the default IIS features to install, and click Next.

Click Install to install the Online Responder role service.

Click Close when prompted.

Page 12: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Part B: Configure the CA to support the Online Responder

In the left pane within Server Manager, drill down to RolesActive Directory Certificate ServicesCertificate Templates.

Page 13: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Right-click the OCSP Response Signing template.

Click Properties.

Click the Security tab, and click Add.

Click Object Types.

Page 14: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Place a checkmark next to Computers, and then click OK.

Key CA, and then click OK.

Place a checkmark next to Enroll and Autoenroll in the Allow column, and then click OK.

Page 15: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Drill down to RolesActive Directory Certificate Serviceslucernepublishing-CA-CACertificate Templates.

Right-click the Certificate Templates folder, and click NewCertificate Template to Issue.

Select the OCSP Response Signing certificate template, and click OK.

Page 16: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Part C: Establish a revocation configuration for the Certification Authority

In the left pane of Server Manager, navigate to RolesActive Directory Certificate Services Online Responder: CARevocation Configuration.

Right-click Revocation Configuration, and click Add Revocation Configuration.

Page 17: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Read the information on the Getting Started screen, and then click Next.

Key LUCERNEPUBLISHING-CA-REV, and click Next.

Verify that the Select a certificate for an Existing enterprise CA radio button is selected, and then click Next.

Page 18: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Verify that the Browse CA certificates published in Active Directory screen option is selected, and then click Browse.

Confirm that the lucernepublishing-CA-CA certificate is selected, and then click OK.

Click Next to continue.

Page 19: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Verify that the Automatically select a signing certificate radio button is selected.

Verify that a checkmark is next to Auto-enroll for an OCSP signing certificate.

Click Next, and then click Finish to configure the revocation configuration.

Page 20: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Revocation (cont.)

Navigate to lucernepublishing-CA-CAIssued Certificates.

Confirm that an OCSP Response Signing Certificate has been issued to the certification authority.

Page 21: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates

Log on to CA as the default administrator of the lucernepublishing.com domain.

Click Start, and then select Server Manager.

In the left pane, expand the Roles node, the Active Directory Certificate Services node, and the Certificate Templates node.

Page 22: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

To create a new certificate template to allow user autoenrollment, right-click the User template.

Click Duplicate Template.

Select Windows Server 2008, Enterprise Edition, and click OK.

Page 23: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

On the General tab, key LUCERNEPUBLISHING-User-Cert in the Template Display Name text box.

Verify that a checkmark is next to the Publish certificate in Active Directory option.

Page 24: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Click the Security tab.

Click Domain Users, and then place a checkmark next to Read, Enroll, and Autoenroll.

Click the Subject Name tab.

Remove the checkmark next to the Include e-mail name in subject name option.

Page 25: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

In the Include this information in the alternate subject name section, remove the checkmark next to E-mail name.

Click the Superseded Templates tab, and click Add.

Select the built-in User certificate template, and then click OK twice to continue.

Page 26: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Right-click the Computer template, and click Duplicate Template.

Select Windows Server 2008, Enterprise Edition, and click OK.

On the General tab, key LUCERNEPUBLISHING-Computer-Cert in the Template Display Name text box.

Page 27: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Verify that a checkmark is next to the Publish certificate in Active Directory option.

Click the Security tab.

Click Domain Computers, and then place a checkmark next to Read, Enroll, and Autoenroll.

Page 28: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Click the Superseded Templates tab, and click Add.

Select the built-in Computer certificate template, and then click OK twice to continue.

Right-click the Web server template, and click Duplicate Template.

Page 29: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Select Windows Server 2008, Enterprise Edition, and click OK.

On the General tab, key LUCERNEPUBLISHING-WebServer-Cert in the Template Display Name text box.

Verify that a checkmark is next to the Publish certificate in Active Directory option.

Page 30: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Click the Security tab, and click Add.

Click Object Types.

Place a checkmark next to Computers, and then click OK.

Key CA, and then click OK.

Page 31: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Place a checkmark next to Enroll and Autoenroll in the Allow column.

Click the Superseded Templates tab, and click Add.

Select the built-in Web Server certificate template, and then click OK twice to continue.

Page 32: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Drill down to RolesActive Directory Certificate Serviceslucernepublishing-CA-CACertificate Templates.

Right-click the Certificate Templates folder, and click NewCertificate Template to Issue.

Page 33: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Configuring Certificate Templates (cont.)

Click LUCERNEPUBLISHING-User-Cert, and click OK.

Repeat the previous two steps to configure the CA to issue the LUCERNEPUBLISHING-Computer-Cert and LUCERNEPUBLISHING-WebServer-Cert certificate templates.

Page 34: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment

Part A: Configure Certificate Autoenrollment in the LUCERNEPUBLISHING.COM domain

Log on to RWDC01 as the default administrator of the lucernepublishing.com domain.

Click the Start button, Administrative Tools, and then Group Policy Management.

Page 35: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Drill down to Forest: lucernepublishing.comDomainsDomain: lucernepublishing.comGroup Policy ObjectsDefault Domain Policy.

Right-click the Default Domain Policy, and then click Edit.

Page 36: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Drill down to the following node: User ConfigurationPoliciesWindows SettingsSecurity SettingsPublic Key Policies.

In the right pane, double-click Certificate Services Client – Auto-Enrollment.

In the Configuration model dropdown box, select Enabled.

Page 37: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Place a checkmark next to the following items: Renew expired certificates, update pending

certificates, and remove revoked certificates.

Update certificates that use certificate templates.

Click OK.

Page 38: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Drill down to the following node: Computer ConfigurationPoliciesWindows SettingsSecurity SettingsPublic Key Policies.

In the right pane, double-click Certificate Services Client – Auto-Enrollment.

In the Configuration model dropdown box, select Enabled.

Page 39: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Drill down to the following node: Computer ConfigurationPoliciesWindows SettingsSecurity SettingsPublic Key Policies.

In the right pane, double-click Certificate Services Client – Auto-Enrollment.

In the Configuration model dropdown box, select Enabled.

Page 40: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Place a checkmark next to the following items: Renew expired certificates, update pending

certificates, and remove revoked certificates.

Update certificates that use certificate templates.

Click OK, and then close the Group Policy Management Editor.

Page 41: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Open a command-prompt window.

Key gpupdate/force, and then close the command-prompt window.

Log on to CA as the default administrator of the lucernepublishing.com domain.

Page 42: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Open a command-prompt window.

Key gpupdate/force, and then close the command-prompt window.

Reboot the CA computer to force both user and computer autoenrollment to take place.

Page 43: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Part B: Install the Certification Authority Web Enrollment role service

Log on to CA as the default administrator of the lucernepublishing.com domain.

Click the Start button, and then select Server Manager.

Page 44: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Drill down to RolesActive Directory Certificate Services.

Right-click Active Directory Certificate Services, and select Add Role Services.

Place a checkmark next to Certification Authority Web Enrollment.

Page 45: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Click Add Required Role Services.

Click Next to continue.

Read the informational message concerning the installation of the Web Server role, and click Next.

Page 46: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Accept the default IIS features to install, and click Next.

Click Install to install the Certification Authority Web Enrollment role service.

Click Close when prompted.

Page 47: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Part C: Request a Web Server Certificate for the CA IIS installation

Click the Start button.

Click Administrative tools, and then select Internet Information Services (IIS) Manager.

In the left pane, double-click the CA node.

Page 48: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Scroll down to the IIS section, and double-click the Server Certificates icon.

In the right pane, click Create Domain Certificate.

Enter the appropriate information as prompted, and click Next.

Page 49: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Click Select next to the Specify Online Certification Authority text box.

Click lucernepublishing-CA-CA, and click OK.

In the Friendly Name text box, key ca.lucernepublishing.com.

Click Finish.

Page 50: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

Part D: Enable Secure Connections to the CA IIS server

In the left pane of IIS Manager, expand the Sites node.

Right-click Default Web Site, and click Edit Bindings.

Click Add.

Page 51: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

In the Type dropdown box, select https.

In the SSL Certificate dropdown box, select ca.lucernepublishing.com.

Click OK, and then click Close.

Page 52: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Managing Certificate Enrollment (cont.)

In the left pane of IIS Manager, drill down to the Default Web SiteCertSrv node.

Double-click CertSrv.

In the middle pane in the IIS section, double-click SSL Settings.

Place a checkmark next to Require SSL, and then click Apply in the Action pane.

Page 53: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

Maintaining a Windows Server 2008 CA

CA Administrator

Certificate Managers

Backup Operators

Auditors

Page 54: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned

The Active Directory Certificate Services (AD CS) role in Windows Server 2008 is a component within Microsoft's larger Identity Lifecycle Management (ILM) strategy. The role of AD CS in ILM is to provide services for managing a Windows public key infrastructure (PKI) for authentication and authorization of users and devices.

Page 55: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned (cont.)

A PKI allows two parties to communicate securely, without any previous communication with each other, through the use of a mathematical algorithm called public key cryptography.

PKI certificates are managed through certificate authorities that are hierarchical, which means that many subordinate CAs within an organization can chain upward to a single root CA.

Page 56: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned (cont.)

Certificate templates are used by a certificate authority to simplify the administration and issuance of digital certificates.

A Certificate Revocation List (CRL) identifies certificates that have been revoked or terminated.

Page 57: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned (cont.)

Autoenrollment is a feature of PKI that is supported by Windows Server 2003 and later, which allows users and computers to automatically enroll for certificates based on one or more certificate templates, as well as using Group Policy settings in Active Directory.

Key archival is the process by which private keys are maintained by the CA for retrieval by a recovery agent.

Page 58: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned (cont.)

Web enrollment enables users to connect to a Windows Server 2008 CA through a Web browser to request certificates and obtain an up-to-date CRL.

The Network Device Enrollment Service (NDES) enables network devices to enroll for certificates within a Windows Server 2008 PKI using the Simple Certificate Enrollment Protocol (SCEP).

Page 59: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned (cont.)

When deploying a Windows-based PKI, two different types of CAs can be deployed: enterprise CAs and standalone CAs. A standalone CA is not integrated with Active Directory and relies on administrator intervention to respond to certificate requests.

Page 60: Configuring Active Directory Certificate Services

Lesson 13Lesson 13

You Learned (cont.)

An enterprise CA integrates with Active Directory. It can use certificate templates as well as Group Policy Objects to allow autoenrollment of digital certificates, as well as storing digital certificates within the Active Directory database for easy retrieval by users and devices.