Showing posts with label r2. Show all posts
Showing posts with label r2. Show all posts

Thursday, March 30, 2017

KN H ow to Install Certificate Services on Windows Server 2008 R2

KN H ow to Install Certificate Services on Windows Server 2008 R2



How to Install Certificate Services on Windows Server 2008 R2

Introduction

Committed Index Certificate Services (AD CS) is the Microsoft implementation of public key infrastructure (PKI). PKI deals with the components and processes for issuing and managing digital certificates that are used for encryption and certification. It is not mandatory to
apply AD CS as part of a Windows Server 2008 Committed Index structure. Even if, many organizations find it useful to deploy this service internally rather than relying on an external provider.
AD CS is the component of Windows Server 2008 that can be used to issue and manage digital certificates. The digital certificates issued by AD CS can be used for encrypting file system (EFS), e-mail encryption, secure sockets layer (SSL), and certification. A server with AD CS installed is referred to as a certification authority (CA).
Digital certificates are used for lop-sided encryption, which requires two keys. The first key is the private key, which is securely stored by the user or computer that a digital certificate has been issued to. The second key is the public key that is distributed to other users and
computers. The data encrypted by one key can only be decrypted by the other key. This relationship ensures safeguard of the encrypted data. Each key is sufficiently generous to preclude computation of the private key via possession of the public key.

How to apply AD CS

AD CS is a complex product with various options for implementations. The implementation options for root and subordinate CAs vary, and you need to be aware of the process for each. Web enrollment is commonly used in many environments and must be configured. You must also manage certificate revocation by using either certificate revocation lists or OCSP. Finally, you must be aware of how to go key archival and recovery.
I believe best practice is, and I’m sure a name will right me if I’m ill-treat, to set up an Enterprise Root CA (Certificate Authority), then set up one or more subordinate CA’s.  You can then make your Root CA unavailable for access and have the subordinates handle all of the traffic without dread of compromising your Root CA.  In this tutorial, we’ll just be installing and configuring a Root CA, but the process is basically the same for the subordinates.
Now that you’ve got some background information, onto the installation/configuration of Windows Server 2008 R2 Certificate Services.
In ‘Server Manager’, select Roles in the left pane, then Add Roles in the right pane.  Place a check mark in the checkbox for Committed Index Certificate Services.  Then click Next.
CA 1
On the ‘Introduction to Committed Index Certificate Services’ window, you can read up on the certificate services technology, how to manage a CA, and naming.  Click Next.
On the ‘Select Role Services’ page, make sure Certification Authority is selected, then selectCertification Authority Web Enrollment, when the ‘Add Roles Wizard’ window appears click the Add Vital Role Services button.  Click Next.
CA 2

CA 3

On the ‘Specify Setup Type’ page, leave Enterprise selected.  Click Next.  On the ‘Specify CA Type’ page, leave Root CA selected and click Next.  On the ‘Set Up Private Key’ page, leaveInitiation a new private key selected and click Next.
On the Configure Cryptography for CA page, you can leave the defaults selected or adjust as necessary for your needs.  You can also pause here and research the providers and hashes as necessary, but for this tutorial and most environments, the default will be enough.  ClickNext.
CA 4

On the ‘Configure CA Name’ page, set the common name to the same as the server name since this server is a domain controller.  This is an acceptable practice.  Leave the ‘Distinguished name suffix’ alone.  Click Next.

CA 5
On the ‘Set Validity Period’ page, feel free to adjust the validity period or leave the default.  This must be adjusted based on your needs.  Click Next.  On the ‘Configure Certificate Database’ page, you can adjust the paths or leave the defaults set.  Click Next.
Next we see the ‘Web Server (IIS)’ page.  You can read the description and check out the associations listed on the page if you’d like.  Click Next.
CA 6

On the ‘Select Role Services’ page, leave the defaults selected.  Click Next.  On the ‘Confirm Installation Selections’ page, you can review your choices, go back and make changes, or clickInstall.  After the ‘Installation Progress’ page finishes, you can view your ‘Results’.
CA 7
You’ve now got a domain controller that is capable of issuing certificates to your servers and users.  You can go back owing to the wizard and install additional CA components, for example, that will allow you to issue certificates to users and computers that are not part of your domain.  That choice is called ‘Certificate Enrollment Web Service’.

Available link for download

Read more »

Saturday, March 11, 2017

Active Directory on Server 2008 R2 Core

Active Directory on Server 2008 R2 Core


IT: How to Install and Manage Active Directory on Server 2008 R2 Core

WindowsActiveDIrectory1
Installing Active Directory on Server Core is not a task that can be achieved using  the Optional Component Setup tool–instead we actually have to use DCPROMO from the command line. Here’s how to do it.
Note: this is part of our ongoing series teaching IT administration basics, and might not apply to everybody.
Before we install Active Directory there are a few things that need to be done first–we need to set static IP information for the network adapter as well as change the name of our server. This all needs to be done from the command line, so lets take a look at how to go about doing these tasks.

Setting a Static IP Address

Active Directory requires that the Server has a static IP assigned, so we need to get a list of the network adapters attached to this server. To do this we use a netsh command:
netsh interface ipv4 show interface
Now that you can see the names of all the network cards in your machine, you can change the settings for a specific card. To change the IP address we again use the netsh command:
netsh interface ipv4 set address name=”Local Area Connection” source=”static” address=”10.10.10.1? mask=”255.255.255.0? gateway=”10.10.10.254?
Where the following values should be substituted:
  • Name – Name of the interface that you wish to change the settings for
  • Address – IP address that you want to assign the interface
  • Mask – The subnet mask for the interface
  • Gateway – The default gateway for the interface
To set up DNS information for the server, we run the following command:
netsh interface ipv4 add dnsservers name=”Local Area Connection” address=”127.0.0.1? index=1 validate=no
Where the following values should be substituted:
  • Name – Name of the interface that you wish to change the settings for
  • Address – IP address of the DNS Server (we are using the loopback address)
  • Index – Specify 1 to set the Primary DNS Server, Specify 2 to set the Secondary DNS Server

Changing The Computer Name

We would also want to rename the server before promoting it to a domain controller, to do that we use the netdom command. You should substitute DC1 in the following command, to whatever you want to call your server.
netdom renamecomputer %computername% /newname:DC1
For the changes to take effect you need to reboot your PC, to do this from the command line run the following command:
shutdown /r /t 0

Installing Active Directory

There is a couple of ways to install Active Directory on a Server Core, however we will go with the answer file method. So I have created an answer file (seen in the screenshot below) this is a basic answer file but if you have special needs you should see  this TechNet article which will give you a full list of parameters. You can create a file exactly like this in notepad and  just call it DCPROMO.txt
So what does this do:
  • Creates a new domain at the root of a new forest called howtogeek.local
  • Sets the forest functional level to Server 2008 R2
  • Installs DNS with an Active Directory Integrated Zone
  • Makes this sever a Global Catalog
  • Sets the AD Restore Mode password to Pa$$w0rd
  • Reboots on completion
You use the answer files by running the following command:
dcpromo :/unattend:”path to answer file”
This will kick off the installation of Active Directory and reboot on completion.
That’s all there is to installing Active Directory on Server Core.

Managing Active Directory

The easiest way to manage a Server Core Server is to use the RSAT (Remote Server Administrator Tools) which allows you to load up MMC consoles on any Windows 7 machine and connect to an instance of the role running on the server. You can grab the RSAT fromhere. The installation is in the form of a Windows Update, once installed open the Turn Windows features on or off option from the Programs and Features section in Control Panel. You need to add the AD DS Snap-ins and Command-line tools, check the screenshot to see how to get there.
Once the components have been added, you can open a run box by hitting the Windows + R key combination and type MMC before hitting enter.
This will open a blank MMC console, click on file and then choose Add/Remove Snap-in..
Choose Active Directory Users and Computers from the list and hit the Add button.
If you are logged in with a Domain Admin account, it will automatically connect to the Active Directory instance, if not you will have to connect to it manually.

Available link for download

Read more »

Thursday, December 29, 2016

Installing Reverse Proxy on Windows Server 2012 R2 Web Application Proxy

Installing Reverse Proxy on Windows Server 2012 R2 Web Application Proxy



Install Windows 2012 R2 with GUI

Install the certificate onto the server
I dont tick "Mark this key as exportable." Because this server will be internet facing.
Change the adfs dns record in DNS to point to the ADFS reverse proxy server
Update the Host file on the server to force adfs.company.co.za always to the primary adfs server.
Install the "Remote Access Roles"
Configure the Application Proxy
All done you should not be able to add additional applications to the reverse proxy.
Doing a quick test to see if ADFS is responding from a remote client using urlhttps://adfs.company.co.za/adfs/services/trust/mex
Ping adfs.company.co.za to make sure it is going to the Proxy
In Internet explorer open the url you should get xml back
Ill releasing blog articles on how to publish the following service in the future:

Available link for download

Read more »