AD CS Deployment Guidance
Before you deploy Active Directory Certificate Services (AD CS), you should be sure that you have an understanding of the AD CS role services (see AD CS Overview) and that you have considered PKI Design (see PKI Design Guidance).
Resources that demonstrate AD CS deployment
AD CS and PKI Step-by-Steps, Labs, Walkthroughs, HowTo, and Examples
Designing and Implementing a PKI: Part II Implementation Phases and Certificate Authority Installation - part 2 of a 5 part series that discusses how to implement a two-tier PKI infrastructure from the Microsoft Ask the Directory Services team blog.
Test Lab Guide: Deploying an AD CS Two Tier PKI Hierarchy - This Test Lab Guide (TLG) shows you how to create a two-tier public key infrastructure (PKI) hierarchy using Windows Server® 2012 and Active Directory Certificate Services (AD CS).
Additional PKI Resources
- Community directory for documentation and information: <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">Windows PKI Documentation Reference and Library(http://social.technet.microsoft.com/wiki/contents/articles/987.windows-pki-documentation-reference-and-library.aspx)
- Frequently asked questions (FAQs) list <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">Active Directory Certificate Services (AD CS) Frequently Asked Questions (FAQ) (http://social.technet.microsoft.com/wiki/contents/articles/1587.active-directory-certificate-services-ad-cs-frequently-asked-questions-faq.aspx)
- Support forum: <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">Windows Server Security Forum (http://social.technet.microsoft.com/Forums/en-US/winserversecurity/threads)
- Product team blog: <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">Windows PKI Blog(http://blogs.technet.com/b/pki/)
- Support Team Blog: <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">Ask the Directory Services team (http://blogs.technet.com/b/askds/)
- Script repository: <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">TechNet Script Center Repository (http://gallery.technet.microsoft.com/scriptcenter) search for Certification, Certificate, or PKI
- chnology overview: <[default] http://ddue.schemas.microsoft.com/authoring/2003/5:LINKTEXT xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5">Active Directory Certificate Services (AD CS) Overview