Summary
This module explained how to select and place AD CS roles, design resilient CA hierarchies, manage trust and administrative boundaries, protect keys, and plan controlled recovery.
Learn more
The following Microsoft sources provide the product behavior and platform guidance referenced in this module:
- What is Active Directory Certificate Services?: Current role-service overview.
- PKI design considerations using Active Directory Certificate Services: Current hierarchy, HSM, cryptography, database, and publication planning guidance.
- Certificate Hierarchy: Current hierarchy concepts.
- How to import third-party CA certificates into the Enterprise NTAuth store: Current support article; it retains an original KB number but isn't used here as previous-version product guidance.
- Certificate Enrollment Web Service overview: Current CES concepts and prerequisites.
- Network Device Enrollment Service guidance: Current NDES role overview.
- The certutil command reference provides current command syntax.