Windows Server 2019: Active Directory Certificate Services
1h 32mIntermediate2019-03-06
Authors

Scott M Burrell
Teacher specializing in HR, marketing, and small business management
Course details
Active Directory Certificate Services (AD CS) allows workstations, servers, and applications to establish trust within an Active Directory forest without the cost of third-party certificates like TLS. This course shows how the AD CS role can be used to verify identity, encrypt communication, and establish trust in a Windows Server 2019 environment. Instructor Scott Burrell dissects the anatomy of a certificate and shows how to configure a public key infrastructure (PKI) in your own domain. He covers multiple ways to manually and automatically issue certificates and revoke certificates when they're no longer needed via a certificate revocation list.
Learning objectives
Identifying trusted certificate authorities
Breaking down the anatomy of a certificate
Installing and configuring AD CS
Backing up and recovering AD CS
Creating and publishing certificate templates
Enforcing certificate enrollment with AD Group Policy
Creating an enrollment agent
Configuring web-based certificate enrollment
Revoking certificates
Learning objectives
Identifying trusted certificate authorities
Breaking down the anatomy of a certificate
Installing and configuring AD CS
Backing up and recovering AD CS
Creating and publishing certificate templates
Enforcing certificate enrollment with AD Group Policy
Creating an enrollment agent
Configuring web-based certificate enrollment
Revoking certificates
Skills covered
Windows ServerServer AdministrationNetwork AdministrationNetwork and System AdministrationMicrosoftDeep Dive (X:Y)
Concepts
Introduction
- Extablishing trust with certificates
- Things you should know
Certificates and Trust
- The purpose of a certificate
- Trusted certificate authorities
- Anatomy of a certificate
- Security properties of certificates
Public Key Infrastructure
- The hierarchy of AD CS
- Installing certificate services
- Configuring a root authority
- Configuring subordinate authorities
- Backup and recovery of AD CS
- Trusting your root CA
Managing Certificate Templates
- Built-in vs. custom templates
- Creating templates for AD
- Security of a certificate template
- Publishing certificate templates
Managing Issued Certificates
- GPO for issuing certificates
- Manual certificate enrollment
- Using enrollment agents
- Installing a Web enrollment server
- Using a web enrollment server
- Managing CRL distribution points
- Using online responders
- Configuring online responders
Conclusion
- Next steps