Ekinlikler
29 Nis 14 - 30 Nis 19
Ayrıntılı teknik oturumlar ve Microsoft mühendisleriyle canlı soru-cevap için 29-30 Nisan tarihleri arasında nihai Windows Server sanal etkinliğine katılın.
Hemen kaydolunBu tarayıcı artık desteklenmiyor.
En son özelliklerden, güvenlik güncelleştirmelerinden ve teknik destekten faydalanmak için Microsoft Edge’e yükseltin.
You can use this guide to deploy server certificates to your Remote Access and Network Policy Server (NPS) infrastructure servers.
This guide contains the following sections.
This guide provides instructions for using Active Directory Certificate Services (AD CS) to automatically enroll certificates to Remote Access and NPS infrastructure servers. AD CS allows you to build a public key infrastructure (PKI) and provide public key cryptography, digital certificates, and digital signature capabilities for your organization.
When you use digital server certificates for authentication between computers on your network, the certificates provide:
By using this guide, you can deploy server certificates to the following types of servers.
Automatic enrollment of server certificates, also called autoenrollment, provides the following advantages.
This guide provides instructions on how to deploy server certificates by using AD CS and the Web Server (IIS) server role in Windows Server 2016. Following are the prerequisites for performing the procedures in this guide.
You must deploy a core network using the Windows Server 2016 Core Network Guide, or you must already have the technologies provided in the Core Network Guide installed and functioning correctly on your network. These technologies include TCP/IP v4, DHCP, Active Directory Domain Services (AD DS), DNS, and NPS.
Not
The Windows Server 2016 Core Network Guide is available in the Windows Server 2016 Technical Library. For more information, see Core Network Guide.
You must read the planning section of this guide to ensure that you are prepared for this deployment before you perform the deployment.
You must perform the steps in this guide in the order in which they are presented. Do not jump ahead and deploy your CA without performing the steps that lead up to deploying the server, or your deployment will fail.
You must be prepared to deploy two new servers on your network - one server upon which you will install AD CS as an Enterprise Root CA, and one server upon which you will install Web Server (IIS) so that your CA can publish the certificate revocation list (CRL) to the Web server.
Not
You are prepared to assign a static IP address to the Web and AD CS servers that you deploy with this guide, as well as to name the computers according to your organization naming conventions. In addition, you must join the computers to your domain.
This guide does not provide comprehensive instructions for designing and deploying a public key infrastructure (PKI) by using AD CS. It is recommended that you review AD CS documentation and PKI design documentation before deploying the technologies in this guide.
Following are technology overviews for AD CS and Web Server (IIS).
AD CS in Windows Server 2016 provides customizable services for creating and managing the X.509 certificates that are used in software security systems that employ public key technologies. Organizations can use AD CS to enhance security by binding the identity of a person, device, or service to a corresponding public key. AD CS also includes features that allow you to manage certificate enrollment and revocation in a variety of scalable environments.
For more information, see Active Directory Certificate Services Overview and Public Key Infrastructure Design Guidance.
The Web Server (IIS) role in Windows Server 2016 provides a secure, easy-to-manage, modular, and extensible platform for reliably hosting websites, services, and applications. With IIS, you can share information with users on the Internet, an intranet, or an extranet. IIS is a unified web platform that integrates IIS, ASP.NET, FTP services, PHP, and Windows Communication Foundation (WCF).
For more information, see Web Server (IIS) Overview.
Ekinlikler
29 Nis 14 - 30 Nis 19
Ayrıntılı teknik oturumlar ve Microsoft mühendisleriyle canlı soru-cevap için 29-30 Nisan tarihleri arasında nihai Windows Server sanal etkinliğine katılın.
Hemen kaydolunEğitim
Modül
Active Directory Sertifika Hizmetleri'ni uygulama ve yönetme - Training
Active Directory Sertifika Hizmetleri'ni uygulama ve yönetme
Sertifikasyon
Microsoft Sertifikalı: Windows Server Hibrit Yönetici Uzmanı - Certifications
Windows Server karma yöneticisi olarak, Windows Server ortamlarını Azure hizmetleriyle tümleştirir ve şirket içi ağlarda Windows Server'ı yönetirsiniz.
Belgeler
EAP-TLS kullanırken sertifika gereksinimleri - Windows Server
Windows Server'da Genişletilebilir Kimlik Doğrulama Protokolü (EAP) Aktarım Katmanı Güvenliği (TLS) veya Korumalı Genişletilebilir Kimlik Doğrulama Protokolü (PEAP)-EAP-TLS kullanırken gereksinimleri açıklar.