Windows Server 2019: Active Directory Certificate Services

Windows Server 2019: Active Directory Certificate Services

1h 32mIntermediate2019-03-06

Authors

Scott M Burrell

Scott M Burrell

Teacher specializing in HR, marketing, and small business management

Course details

Active Directory Certificate Services (AD CS) allows workstations, servers, and applications to establish trust within an Active Directory forest without the cost of third-party certificates like TLS. This course shows how the AD CS role can be used to verify identity, encrypt communication, and establish trust in a Windows Server 2019 environment. Instructor Scott Burrell dissects the anatomy of a certificate and shows how to configure a public key infrastructure (PKI) in your own domain. He covers multiple ways to manually and automatically issue certificates and revoke certificates when they're no longer needed via a certificate revocation list.

Learning objectives
Identifying trusted certificate authorities
Breaking down the anatomy of a certificate
Installing and configuring AD CS
Backing up and recovering AD CS
Creating and publishing certificate templates
Enforcing certificate enrollment with AD Group Policy
Creating an enrollment agent
Configuring web-based certificate enrollment
Revoking certificates

Skills covered

Windows ServerServer AdministrationNetwork AdministrationNetwork and System AdministrationMicrosoftDeep Dive (X:Y)

Concepts

Introduction

  • Extablishing trust with certificates
  • Things you should know

Certificates and Trust

  • The purpose of a certificate
  • Trusted certificate authorities
  • Anatomy of a certificate
  • Security properties of certificates

Public Key Infrastructure

  • The hierarchy of AD CS
  • Installing certificate services
  • Configuring a root authority
  • Configuring subordinate authorities
  • Backup and recovery of AD CS
  • Trusting your root CA

Managing Certificate Templates

  • Built-in vs. custom templates
  • Creating templates for AD
  • Security of a certificate template
  • Publishing certificate templates

Managing Issued Certificates

  • GPO for issuing certificates
  • Manual certificate enrollment
  • Using enrollment agents
  • Installing a Web enrollment server
  • Using a web enrollment server
  • Managing CRL distribution points
  • Using online responders
  • Configuring online responders

Conclusion

  • Next steps
40,000 Toman