Summary
In this module, you learned to deploy and harden an offline root CA and enterprise issuing CAs, prepare CAPolicy.inf, and complete controlled signing procedures. You also learned to configure AIA/CDP and CRLs, publish CA artifacts to AD DS and HTTP, manage root trust and NTAuth, validate certificate chains, capture configuration baselines, back up the CA database and keys, and plan CA renewal.
Learn more
- PKI design considerations using Active Directory Certificate Services
- CAPolicy.inf syntax
- Install the Certification Authority on Windows Server
- Install-AdcsCertificationAuthority
- Configure the CDP and AIA extensions on a CA
- Command reference for
certutil - Adding static-content MIME mappings in IIS
- Import a third-party CA certificate into the Enterprise NTAuth store