Deploy offline root and issuing Active Directory Certificate Services certification authorities
Intermediate
Administrator
Windows Server
Deploy, harden, publish, and validate an offline root certification authority with enterprise issuing certification authorities.
Learning objectives
By the end of this module, you'll be able to:
- Prepare role-specific
CAPolicy.inffiles and explain installation, renewal, and non-retroactive behavior. - Install standalone root and enterprise subordinate certification authorities.
- Complete a controlled offline root signing workflow.
- Configure certificate publication, revocation, policy, exit module, and service baselines.
- Publish certification authority artifacts to directory and web locations.
- Validate trust, chain building, certificate retrieval, and revocation retrieval from clean clients.
- Export a protected baseline, back up certification authority state, and define renewal plans.
Prerequisites
- Familiarity with Windows Server administration.
- Familiarity with Active Directory Domain Services.
- Understanding of public key infrastructure concepts.