Showing posts with label services. Show all posts
Showing posts with label services. Show all posts
Thursday, March 30, 2017
KN H ow to Install Certificate Services on Windows Server 2008 R2
KN H ow to Install Certificate Services on Windows Server 2008 R2
Introduction
Committed Index Certificate Services (AD CS) is the Microsoft implementation of public key infrastructure (PKI). PKI deals with the components and processes for issuing and managing digital certificates that are used for encryption and certification. It is not mandatory toapply AD CS as part of a Windows Server 2008 Committed Index structure. Even if, many organizations find it useful to deploy this service internally rather than relying on an external provider.
AD CS is the component of Windows Server 2008 that can be used to issue and manage digital certificates. The digital certificates issued by AD CS can be used for encrypting file system (EFS), e-mail encryption, secure sockets layer (SSL), and certification. A server with AD CS installed is referred to as a certification authority (CA).
Digital certificates are used for lop-sided encryption, which requires two keys. The first key is the private key, which is securely stored by the user or computer that a digital certificate has been issued to. The second key is the public key that is distributed to other users and
computers. The data encrypted by one key can only be decrypted by the other key. This relationship ensures safeguard of the encrypted data. Each key is sufficiently generous to preclude computation of the private key via possession of the public key.
How to apply AD CS
AD CS is a complex product with various options for implementations. The implementation options for root and subordinate CAs vary, and you need to be aware of the process for each. Web enrollment is commonly used in many environments and must be configured. You must also manage certificate revocation by using either certificate revocation lists or OCSP. Finally, you must be aware of how to go key archival and recovery.I believe best practice is, and Im sure a name will right me if Im ill-treat, to set up an Enterprise Root CA (Certificate Authority), then set up one or more subordinate CAs. You can then make your Root CA unavailable for access and have the subordinates handle all of the traffic without dread of compromising your Root CA. In this tutorial, well just be installing and configuring a Root CA, but the process is basically the same for the subordinates.
Now that youve got some background information, onto the installation/configuration of Windows Server 2008 R2 Certificate Services.
In Server Manager, select Roles in the left pane, then Add Roles in the right pane. Place a check mark in the checkbox for Committed Index Certificate Services. Then click Next.
On the Introduction to Committed Index Certificate Services window, you can read up on the certificate services technology, how to manage a CA, and naming. Click Next.
On the Select Role Services page, make sure Certification Authority is selected, then selectCertification Authority Web Enrollment, when the Add Roles Wizard window appears click the Add Vital Role Services button. Click Next.
On the Specify Setup Type page, leave Enterprise selected. Click Next. On the Specify CA Type page, leave Root CA selected and click Next. On the Set Up Private Key page, leaveInitiation a new private key selected and click Next.
On the Configure Cryptography for CA page, you can leave the defaults selected or adjust as necessary for your needs. You can also pause here and research the providers and hashes as necessary, but for this tutorial and most environments, the default will be enough. ClickNext.
On the Configure CA Name page, set the common name to the same as the server name since this server is a domain controller. This is an acceptable practice. Leave the Distinguished name suffix alone. Click Next.
On the Set Validity Period page, feel free to adjust the validity period or leave the default. This must be adjusted based on your needs. Click Next. On the Configure Certificate Database page, you can adjust the paths or leave the defaults set. Click Next.
Next we see the Web Server (IIS) page. You can read the description and check out the associations listed on the page if youd like. Click Next.
On the Select Role Services page, leave the defaults selected. Click Next. On the Confirm Installation Selections page, you can review your choices, go back and make changes, or clickInstall. After the Installation Progress page finishes, you can view your Results.
Youve now got a domain controller that is capable of issuing certificates to your servers and users. You can go back owing to the wizard and install additional CA components, for example, that will allow you to issue certificates to users and computers that are not part of your domain. That choice is called Certificate Enrollment Web Service.
Available link for download
Saturday, October 29, 2016
Install Active Directory Domain Services ADDS Role
Install Active Directory Domain Services ADDS Role
Install Active Directory Domain Services (ADDS) Role
Launch Server ManagerClick Add Roles and Features
Click Next
Select Role-based or feature-based installation and press Next
Since I am installing my forest locally I will select Select a server from the server pool
Select the server, in my case its DC2012
Press Next
Check off Active Directory Domain Services
When you check off Active Directory Domain Services a dialog window will pop up
Press Add Features
Press Next
Press Next on the features section, you do not need to check anything off here.
Some things will be checked off because you selected Active Directory Domain Services in the last section.
Read the important things to note about this installation.
Press Next
Press Install
Installation will complete. Press Close
Configure ADDS Forest and Domain
Next time your launch Server Manager. You will see a notification icon. Press the exclamation point. Select Promote this server to a domain controllerWarning: Do not create new Active Directory forests with the same name as an external DNS name. For example, if your Internet DNS URL is http://contoso.com, you must choose a different name for your internal forest to avoid future compatibility issues. That name should be unique and unlikely for web traffic. For example: corp.contoso.com.
Select Add a new forest
Specify the root domain name, in my case its pintolab.net
Press Next
In my new lab all servers will be Windows Server 2012. So I will be setting the functional level to Windows Server 2012. To understand more about Functional Levels please visit: http://technet.microsoft.com/en-us/library/cc771294.aspx
I will select Domain Name System (DNS), because ADDS needs DNS. This machine will function as the DNS server for the whole forest.
Enter a password for Directory Services Restore Mode (DSRM)
Press Next
Press Next. If there was an existing DNS server you would be able to change this option.
I like to set my domain name to 8 characters or less so that the NetBIOS name is the same as the domain name. If my domain name was longer, it would have truncated it. You can however make this anything you want. More information on NetBIOS Domain Names: http://technet.microsoft.com/en-us/library/cc961556.aspx
Press Next
Press Next
Press Next
Press Install
In my case I got a couple of warnings. The most important warning was the one saying I am using DHCP instead of an assigned IP Address. Its important to make sure your Domain Controller and DNS Servers use static IPs.
After Installation, Press Close
Setup will reboot the server, you will notice that the domain name is now in front of the username
One thing to take note of is that when DNS gets installed it will point the preferred DNS Server to itself and within DNS it will use the DNS Server that was in there before as a forwarder.
Managing Active Directory
Open Server Manager
Select AD DS
Right Click the Server Name, I find this is the quickest way to get to the Management Tools, since they removed the good ole start menu.
When you right click the server name you should see the familiar AD tools.
Active Directory Users and Computers thankfully has the same look and feel as previous versions.
Available link for download
Subscribe to:
Posts (Atom)