Implementing Active Directory Certificate Services Complete Scenario - 20412d M6

preview_player
Показать описание
Implementing AD CS - Microsoft Exam 70-412 prep.
20412D Module 06 Labs A - B
In this lab you will learn how to deploy a stand-alone root CA and an enterprise subordinate CA as well as configure certificate templates, enrollment, and revocation. You will also learn how to configure and perform private key archival and recovery. This lab contains Lab A – Lab B.
Lab steps are provided at the bottom of main screen: send email if you need pdf version of lab:
Objective
The objectives of this lab are to learn how to:
• Deploy a stand-alone root CA
• Deploy an enterprise subordinate CA
• Configure certificate templates
• Configure certificate enrollment
• Configure certificate revocation
• Configure and perform private key archival and recovery

Scenario
Lab A: Deploying and Configuring a CA Hierarchy
As A. Datum Corporation has expanded, its security requirements have also increased. The security department is particularly interested in enabling secure access to critical websites, and in providing additional security for features. To address these and other security requirements, A. Datum has decided to implement a PKI using the AD CS role in Windows Server 2012.

As one of the senior network administrators at A. Datum, you are responsible for implementing the AD CS deployment.

Lab B: Deploying and Managing Certificates
As A. Datum Corporation has expanded, its security requirements have also increased. The security department is particularly interested in enabling secure access to critical websites, and in providing additional security for features such as drive encryption, smart cards, and the Windows 7 and Windows 8 DirectAccess feature. To address these and other security requirements, A. Datum has decided to implement a PKI using the AD CS role in Windows Server 2012.

As one of the senior network administrators at A. Datum, you are responsible for implementing the AD CS deployment. You will deploy the CA hierarchy, develop the procedures and process for managing certificate templates, and deploy and revoke certificates.
Рекомендации по теме
Комментарии
Автор

Thank you for the lesson! I was able to get my Two Tier Hierarchy operational in my production environment! You rock!

chrisbethel
Автор

@37:39 I am getting the error after Installing New CA Certificate on the SubCA that reads:

"Cannot verify certificate chain. Do you wish to ignore the error and continue? The revocation function was unable to check revocation because the revocation server was offline. 0x80092013 (-2146885613 CRYPT_E_REVOCATION_OFFLINE)"

I have started over once because I had the error previously and assumed I had made a mistake somewhere, but now I am getting the error again. Any ideas?

chrisbethel
Автор

Hi how to get the MS labs to go more than 2 hours?

zoltron
Автор

Just wasting time move back snd forth from domain to work group.Secondly, it as first step not to use existing ip schema for domain servers and stand alone root server because stand alone root ca must not be presented on dns. and last for internal computers and users more important after personal certificates are presented not to use password but PIV cards.
Microsoft recommand not to use LDAP as file for CDP or AIA. One more important step before configuration CDP or AIA it needs to create IIS server with virtual directory for CDP or AIA and make notes to present path.

ilyashick