Practical Guide to PKI with Windows Server
Book information
Description
If you are looking for a hands on guide to implementing a complete Certificate Authority using Windows Server, then this book is for you. This book demonstrates the process for creating a Certificate Authority using Active Directory Certificate Services using Windows Serer 2019.What's inside?A 398-page complete guide to implementing a Two-Tier Certificate Authority using Windows Server 2019.An in-depth step-by-step guide for building all components of a CA.A quick start guide for quickly creating a CA using AD CS.A guide to implementing an Offline Root CA and an Enterprise CA.A guide to implementing OCSP with AD CS.A guide to installing and configuring Hyper-V.Instructions using the GUI and the CLI for installation and configuration.Over 350 screenshots and diagrams.Over 125 configuration commands and sample configurations.Table of Contents Included in the book are 12 Chapters which explain the process for creating a Certificate Authority using Active Directory Certificate Services: Public Key Infrastructure OverviewCertificate Authority Test EnvironmentDomain Controller and Workstation SetupOffice Root CA SetupSubordinate CA SetupDeploy Root and Subordinate CertificatesOnline Responder Role ConfigurationPrivate Key Archive and RecoveryCertificate Template CustomizationCertificate EnrollmentAD CS Post-Implementation TasksAD CS Quick Start Also included is a Glossary, a list of all commands used in the book and a complete Index. Who Is This Book For? The purpose of this book is to create a Certificate Authority using Active Directory Certificate Services (AD CS) with Microsoft Windows Server. This book offers a comprehensive step-by-step guide that demonstrates how to successfully create a Certificate Authority using those technologies. This book also explains each step, the necessity of that step, and the importance of that step within the Certificate Authority. The results of this book will create a Certificate Authority that can issue certificates internally within an organization in a secure manner, using best practices. This book is meant for developers, network administrators and systems administrators who have a basic understanding of Windows Server and Public Key Infrastructures and need to deploy a Certificate Authority rapidly within their environment for various purposes. By using the steps provided in this book, there will be a Certificate Authority framework created that can be customized for whatever requirements are needed in any environment. This book is also meant to be used by developers, network administrators and system administrators who can interpret this guide and modify it for their existing environment. Simply following this guide will not implement a functioning PKI for your organization, you will need to modify the steps accordingly to make it function properly. This means creating different servers, modifying steps for different Active Directory domains, modifying LDAP settings, modifying file paths, creating different certificates, and other critical steps as needed. The contents of this book are presented in a thorough, but easy to follow manner. Screenshots are provided for important steps for verification purposes and to demonstrate how the environment should be configured. About the Author Preface Who Is This Book For? Conventions Used in This Book Text Conventions Information Boxes Introduction Goals of This Book What Won't This Book Cover? Before You Start Software Requirements AD CS Installation and Configuration Options Virtualization Requirements Organization of this Book Chapter 1 - Public Key Infrastructure Overview What Is a Public Key Infrastructure? Active Directory Certificate Services Overview Active Directory Certificate Services Roles Certificate Authority Hierarchies One-Tier Certificate Authority Two-Tier Certificate Authority Three-Tier Certificate Authority Certificate Authority and PKI Terminology X.509 Certificates Certificate Attributes Certificate Revocation Lists Certificate Types Private Enterprise Numbers Why Use an Offline Root CA? Windows Certificate Management Public Key Infrastructure Overview Next Steps Chapter 2 - Certificate Authority Test Environment Certificate Authority Environment Design and Overview Certificate Authority Design Considerations Certificate Hierarchy Overview AD CS Internal URLs AD CS Important Files AD CS Important Files - TFS-CA01 AD CS Important Files - TFS-DC01 AD CS Important Files - TFS-ROOT-CA AD CS Security Considerations Certificate Authority Naming Conventions Hyper-V Configuration Hyper-V Requirements Hyper-V Installation Enable Hyper-V using the Control Panel Enable Hyper-V using PowerShell Enable Hyper-V using DISM Hyper-V Network Setup Hyper-V Virtual Machine Generation Hyper-V Checkpoints Hyper-V Virtual Machine Creation Hyper-V Virtual Machine Connection Hyper-V Disk Virtual Floppy Disk Management Certificate Authority Test Environment Next Steps Chapter 3 - Domain Controller and Workstation Setup Domain Controller Server Setup AD DS Role Installation AD DS Role Installation - GUI Installation AD DS Role Installation - CLI Installation AD DS Role Configuration AD DS Role Configuration - GUI Configuration AD DS Role Configuration - CLI Configuration AD DS Role Configuration - Validation Create an Active Directory OU Structure Create an Active Directory OU Structure - GUI Configuration Create an Active Directory OU Structure - CLI Configuration Create Domain User Accounts Create Domain User Accounts - GUI Configuration Create Domain User Accounts - CLI Configuration Workstation Creation and Domain Join LDAP over SSL for Active Directory Domain Controller and Workstation Next Steps Chapter 4 - Offline Root CA Setup Root CA Server Setup Optional: Add BitLocker on the Root CA Add BitLocker on the Root CA - GUI Installation Add BitLocker on the Root CA - CLI Installation Optional: Configure Group Policy for BitLocker on the Root CA Optional: Enable BitLocker on the Root CA Optional: Test BitLocker on the Root CA Test the BitLocker Recovery Key Mount the BitLocker Hard Disk on Another Device Back Up the BitLocker Recovery Key Optional: Disable Windows Update on the Root CA Root CA Server Local Policies Root CA CAPolicy.inf Installation Root CA AD CS Role Installation Root CA AD CS Role Installation - GUI Installation Root CA AD CS Role Installation - CLI Installation Root CA AD CS Role Configuration Root CA AD CS Role Configuration - GUI Configuration Root CA AD CS Role Configuration - CLI Configuration Root CA Validation Root CA CRL Configuration Enable Auditing on the Root CA Root CA CDP and AIA Configuration Root CA CDP and AIA Configuration - GUI Configuration Root CA CDP and AIA Configuration - CLI Configuration Root CA Certificate and CRL Export Root CA Server Restart Root CA Next Steps Chapter 5 - Subordinate CA Setup Subordinate CA Server Setup Create CNAME Records in DNS Create CNAME Records in DNS - GUI Configuration Create CNAME Records in DNS - CLI Configuration Create CNAME Records in DNS - Validation Subordinate CA CAPolicy.inf Installation Subordinate CA AD CS Role Installation Subordinate CA AD CS Role Installation - GUI Installation Subordinate CA AD CS Role Installation - CLI Installation Subordinate CA AD CS Role Configuration Subordinate CA AD CS Role Configuration - GUI Configuration Subordinate CA AD CS Role Configuration - CLI Configuration Subordinate CA Validation Create the CertData Virtual Directory Create the CertData Virtual Directory - GUI Configuration Create the CertData Virtual Directory - CLI Configuration Create the CertData Virtual Directory - Validation Enable Double Escaping in IIS Subordinate Certificate Creation Set Maximum Certificate Age Modify the CertEnroll Virtual Directory Modify the CertEnroll Virtual Directory - GUI Configuration Modify the CertEnroll Virtual Directory - CLI Configuration Modify the CertEnroll Virtual Directory - Validation Enable Auditing on the Subordinate CA Subordinate CA CDP and AIA Configuration Subordinate CA CDP and AIA Configuration - GUI Configuration Subordinate CA CDP and AIA Configuration - CLI Configuration Certification Practice Statement Document Windows Firewall Configuration Add the Root CA to Active Directory Verify PKI Infrastructure Subordinate CA Server Restart Subordinate CA Next Steps Chapter 6 - Deploy Root and Subordinate Certificates Prepare the Root and Subordinate Certificates Deploy the Root and Subordinate Certificates to the Domain Deploy the Root Certificate to the Domain Controller Internal Certificate File Deployment Folder Internal Certificate File Deployment Folder - GUI Configuration Internal Certificate File Deployment Folder - CLI Configuration Internal Certificate File Deployment Folder - Validation Deploy Root and Subordinate Certificates Next Steps Chapter 7 - Online Responder Role Configuration Add the Online Responder Role Add the Online Responder Role - GUI Installation Add the Online Responder Role - CLI Installation Enable the Online Responder Role Enable the Online Responder Role - GUI Configuration Enable the Online Responder Role - CLI Configuration Enable the Online Responder Role - Validation Add the OCSP URL to the Subordinate CA Add the OCSP URL to the Subordinate CA - GUI Configuration Add the OCSP URL to the Subordinate CA - CLI Configuration Configure and Publish the OCSP Response Signing Certificate Revocation Configuration for the Online Responder Role Enable Auditing on the Online Responder Add the OCSP URL to Group Policy Verify OCSP Status Test OCSP Connectivity Online Responder Role Limitations Online Responder Role Next Steps Chapter 8 - Private Key Archive and Recovery Create the Key Recovery Agent Certificate Template Deploy the Key Recovery Agent Certificate Configure the Certificate Authority for Key Recovery Private Key Archive and Recovery Next Steps Chapter 9 - Certificate Template Customization Active Directory Certificate Templates User Certificate Template Creation User Certificate Private Key Recovery Computer Certificate Template Creation Web Server Certificate Template Creation Delete Unnecessary Certificate Templates Active Directory Certificate Services Web Enrollment Certificate Template Deployment Next Steps Chapter 10 - Certificate Enrollment User Certificate Auto-Enrollment Computer Certificate Auto-Enrollment Optional: Deploy Certificates to a Linux Server Deploy Certificates to a Linux Server - Server Setup Deploy Certificates to a Linux Server - CSR Request Deploy Certificates to a Linux Server - Apache Setup Deploy Certificates to a Linux Server - Nginx Setup Optional: Deploy Certificates to Android Optional: Deploy Certificates to iOS Optional: Deploy Certificates to macOS Certificate Enrollment Next Steps Chapter 11 - AD CS Post-Implementation Tasks Virtual Floppy Disk Deletion Root CA Shut Down Renewing the Root CA CRL Manually Back Up the PKI Infrastructure Active Directory Former Certificate Authorities Test Active Directory Certificate Services on your Domain AD CS Post-Implementation Tasks Next Steps Chapter 12 - AD CS Quick Start AD CS Quick Start - Environment Setup AD CS Quick Start - AD DS Setup AD DS Setup - AD DS Installation AD DS Setup - AD DS Configuration AD DS Setup - OU Configuration AD DS Setup - Administrator Configuration AD DS Setup - Next Steps AD CS Quick Start - Root CA Setup Root CA Setup - Local Policies Root CA Setup - CAPolicy.inf Installation Root CA Setup - AD CS Role Installation Root CA Setup - AD CS Role Configuration Root CA Setup - Root CA Validation Root CA Setup - Root CA CRL Configuration Root CA Setup - CDP and AIA Configuration Root CA Setup - Root CA Certificate and CRL Export Root CA Setup - Next Steps AD CS Quick Start - Subordinate CA Setup Subordinate CA Setup - Create CNAME Records in DNS Subordinate CA Setup - CAPolicy.inf Installation Subordinate CA Setup - AD CS Role Installation Subordinate CA Setup - AD CS Role Configuration Subordinate CA Setup - Subordinate CA Validation Subordinate CA Setup - Create the CertData Virtual Directory Subordinate CA Setup - Enable Double Escaping in IIS Subordinate CA Setup - Subordinate Certificate Creation Subordinate CA Setup - Set Maximum Certificate Age Subordinate CA Setup - Modify the CertEnroll Virtual Directory Subordinate CA Setup - CDP and AIA Configuration Subordinate CA Setup - CPS Document Subordinate CA Setup - Windows Firewall Configuration Subordinate CA Setup - Add the Root CA to Active Directory Subordinate CA Setup - Verify PKI Infrastructure Subordinate CA Setup - Next Steps AD CS Quick Start - Post-Implementation Tasks Post-Implementation Tasks - Virtual Floppy Disk Deletion Post-Implementation Tasks - Root CA Shut Down AD CS Quick Start - Next Steps Glossary Commands Graphical Tools Using Windows Server Tools Graphical Tools Using the Microsoft Management Console Cmdlets for Managing Windows Server Command Line Tools for Managing Windows Server Index
Similar books
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF
Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix
2008 · PDF