The Place For Free Online Training Courses

Installing Certificate Services Windows 2008

In most cases, you will install at least a two-tiered structure, installing first a standalone, then an enterprise CA. In larger organizations, you will deploy several tiers and install several servers in each tier except for the root. Servers hosting the AD CS role should be configured with the following capabilities whether they are physical or virtual:

Use the buttons below to navigate through the lesson

The supported features based on the edition of Windows Server 2008.

Supported Components and Features Web Standard Enterprise Data Centre
Key archival No No Yes Yes
Role Separation No No Yes Yes
Certificate Manager restrictions No No Yes Yes
Delegated enrollment agent
restrictions
No No Yes Yes

You must prepare your environment before installing AD CS. The prerequisites for an AD CS installation include the following:

Right click Roles. Select Add Roles. Click Next. Select Active Directory Certificate Services and click Next. Click Next. Select Certification Authority and click Next. Select Standalone and click Next. Select Root CA and click Next. Select Create a new private key Select Create a new private key and click Next. Select the suggested cryptographic service provider (CSP). Select a key character length of 2048. Select the sha1 hash algorithm for signing certificates issued by this CA and click Next. Create a common name and click Next. Select a suitable validity period and click Next. Select Database and logfile locations and click Next. Review settings and click Install. Click Close. Standalone Root CA is now installed. Disconnect this CA from the network after the Group Policy cycle has been updated, to provide further protection for this server.

Exit mobile version