Web enrollment for a Standalone CA

Vicky Wang 2,646 Reputation points
2020-08-07T07:41:44.84+00:00

After installing Certification services and creating a Standalone CA on a Windows Server 2016 or Windows Server 2019 server member of Workgroup what else should I do in order to allow other servers request certificates?

Should I install Certification Authority Web Enrollment, Certification Enrollment Web Services or both?

Which certificate should I use to enable HTTPS access to the certsrv site?

I found many pages describing the steps in an AD domain environment, very few for a Standalone CA in Workgroup environment.

Source Link :https://social.technet.microsoft.com/Forums/en-US/79db9f85-1740-4bea-af91-0964ea94de1b/web-enrollment-for-a-standalone-ca?forum=winserversecurity

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,737 questions
0 comments No comments
{count} votes

Accepted answer
  1. Fan Fan 15,301 Reputation points Microsoft Vendor
    2020-08-07T08:04:51.017+00:00

    Based on my research the CA Web Enrollment role service will be helpful.

    Certification Enrollment Web Services used with ADDS together.The computer on which the Certificate Enrollment Web Service is to be installed must be a member of the domain and must be running Windows Server 2008 R2 or Windows Server 2012.

    For a stand alone CA,the CA Web Enrollment role service will be helpful.This service allow you to connect to the CA by using a web browser and performing common tasks, such as:

    Requesting certificates from the CA.
    Requesting the CA's certificate.
    Submitting a certificate request by using a PKCS #10 file.
    Retrieving the CA's certificate revocation list (CRL).

    CA Web Enrollment is useful when you interact with a stand-alone CA because the Certificates Microsoft Management Console (MMC) snap-in cannot be used to interact with a stand-alone CA. Enterprise CAs can accept certificate requests through the Certificates snap-in or the CA Web Enrollment role service pages.

    The Certification Authority (CA) Web Enrollment role service provides a set of web pages that allow interaction with the Certification Authority role service. These web pages are located at https://<servername>/certsrv, where <servername> is the name of the server that hosts the hosts the CA Web Enrollment pages.
    For more information you can refer to the following links:

    Certificate Enrollment Web Service Guidance

    Certificate Enrollment Web Services

    Certification Authority Web Enrollment Guidance

    How Certification Authority Web Enrollment Differs from Certificate Enrollment Web Services

    Also,to the certificates ,the clients should also trust the CA manually.You can refer to the steps in the following link:

    Installing the trusted root certificate

    0 comments No comments

0 additional answers

Sort by: Most helpful