Deploy offline root and issuing Active Directory Certificate Services certification authorities

Intermediate
Administrator
Windows Server

Deploy, harden, publish, and validate an offline root certification authority with enterprise issuing certification authorities.

Learning objectives

By the end of this module, you'll be able to:

  • Prepare role-specific CAPolicy.inf files and explain installation, renewal, and non-retroactive behavior.
  • Install standalone root and enterprise subordinate certification authorities.
  • Complete a controlled offline root signing workflow.
  • Configure certificate publication, revocation, policy, exit module, and service baselines.
  • Publish certification authority artifacts to directory and web locations.
  • Validate trust, chain building, certificate retrieval, and revocation retrieval from clean clients.
  • Export a protected baseline, back up certification authority state, and define renewal plans.

Prerequisites

  • Familiarity with Windows Server administration.
  • Familiarity with Active Directory Domain Services.
  • Understanding of public key infrastructure concepts.