PKI Infrastructure
My PKI Wake-Up Call
What is Public Key Infrastructure (PKI)?
Why PKI Matters in Enterprise
PKI Architecture and Hierarchy
The Two-Tier CA Model (My Standard)
Root CA (Offline)
Subordinate/Issuing CA (Online)
PKI Certificate Flow
Planning PKI Deployment
Server Specifications
Certificate Validity Periods
CAPolicy.inf Configuration
Installing Root CA (Offline)
Step 1: Prepare Server
Step 2: Create CAPolicy.inf
Step 3: Install Root CA Role
Step 4: Export Root CA Certificate and CRL
Step 5: Secure and Power Off Root CA
Installing Issuing CA (Online)
Step 1: Publish Root CA Certificate to AD
Step 2: Prepare Issuing CA Server
Step 3: Request Subordinate CA Certificate from Root CA
Step 4: Issue Certificate from Root CA
Step 5: Install Issued Certificate on Issuing CA
Step 6: Configure CRL and AIA
Certificate Templates
Viewing Default Templates
Duplicating and Customizing Templates
Publishing Templates to CA
Auto-Enrollment Configuration
GPO Configuration for Certificate Auto-Enrollment
Manual Certificate Enrollment
Certificate Revocation
Revoking Certificates
CRL Management
Online Responder (OCSP)
Smart Card Authentication
Configure Smart Card Logon Template
Enable Smart Card Logon in AD
Monitoring and Maintenance
Health Checks
Backup CA
Restore CA
Certificate Database Maintenance
Security Best Practices
1. Protect CA Private Key
2. Restrict CA Administration
3. Enable Auditing
4. Implement Key Archival (for recovery)
Real-World Scenarios
Scenario 1: Issue SSL Certificate for ADFS
Scenario 2: Configure 802.1X with Computer Certificates
Scenario 3: Email Encryption (S/MIME)
Troubleshooting Common Issues
Issue: Certificate Auto-Enrollment Not Working
Issue: CRL Not Accessible
Issue: Certificate Validation Fails
Conclusion
Further Reading
Last updated