Module 08 - Deploying and Managing AD CS
Module 08 - Deploying and Managing AD CS
3. In the Control Panel window, click View network status and tasks.
4. In the Network and Sharing Center window, click Change advanced sharing settings.
5. Under Guest or Public (current profile), select the Turn on file and printer sharing option, and
then click Save changes.
6. Switch to LON-SVR1.
9. In the Network and Sharing Center window, click Change advanced sharing settings.
10. Under Domain (current profile), select the Turn on file and printer sharing option, and then
click Save changes.
1. Switch to CA-SVR1.
10. On the Select role services page, ensure that Certification Authority is selected, and then
click Next.
12. On the Installation progress page, after installation completes successfully, click the Configure
Active Directory Certificate Services on the destination server** text.
14. On the Role Services page, select Certification Authority, and then click Next.
15. On the Setup Type page, ensure that Standalone CA is selected, and then click Next.
16. On the CA Type page, ensure that Root CA is selected, and then click Next.
17. On the Private Key page, ensure that Create a new private key is selected, and then click Next.
18. On the Cryptography for CA page, keep the default selections for Select a cryptographic
provider and Select the hash algorithm for signing certificates issued by this CA, but set
the Key length to 4096, and then click Next.
19. On the CA Name page, in the Common name for this CA text box, type AdatumRootCA, and
then click Next.
25. On CA-SVR1, in Server Manager, click Tools, and then click Certification Authority.
26. In the certsrv – [Certification Authority (Local)] console, right-click AdatumRootCA, and then
click Properties.
27. In the AdatumRootCA Properties dialog box, click the Extensions tab.
28. In the Select extension drop-down list, click CRL Distribution Point (CDP), and then click Add.
30. In the Variable drop-down list, click <CaName>, and then click Insert.
31. In the Variable drop-down list, click <CRLNameSuffix>, and then click Insert.
32. In the Variable drop-down list, click <DeltaCRLAllowed>, and then click Insert.
33. In the Location text box, position the cursor at the end of the URL, type .crl, and then click OK.
36. Include in CRLs. Clients use this to find Delta CRL locations
40. In the Variable drop-down list, click <ServerDNSName>, and then click Insert.
41. In the Location text box, type an underscore ( _ ), in the Variable drop-down list,
click <CaName>, and then click Insert. Position the cursor at the end of the URL.
42. In the Variable drop-down list, click <CertificateName>, and then click Insert.
43. In the Location text box, position the cursor at the end of the URL, type .crt, and then click OK.
44. Select the Include in the AIA extension of issued certificates check box, and then click OK.
50. In the Certificate dialog box, click the Details tab, and then click Copy to File.
51. In the Certificate Export Wizard, on the Welcome page, click Next.
52. On the Export File Format page, select DER encoded binary X.509 (.CER), and then click Next.
53. On the File to Export page, click Browse, in the File name text box, type \\lon-svr1\C$, and
then press Enter.
54. In the File name text box, type RootCA, click Save, and then click Next.
57. In the Cert Enroll folder, select both files, right-click the highlighted files, and then click Copy.
58. In the File Explorer address bar, type \\lon-svr1\C$, and then press Enter.
59. Right-click the empty space, and then click Paste.
1. On LON-SVR1, click Start, click Server Manager, and then click Add roles and features.
5. On the Select server roles page, select Active Directory Certificate Services.
6. When the Add Roles and Features Wizard displays, click Add Features, and then click Next.
10. When the Add Roles and Features Wizard displays, click Add Features, and then click Next.
12. On the Installation progress page, after installation is successful, click the Configure Active
Directory Certificate Services on the destination server text.
14. On the Role Services page, select both Certification Authority and Certification Authority
Web Enrollment, and then click Next.
15. On the Setup Type page, select Enterprise CA, and then click Next.
16. On the CA Type page, click Subordinate CA, and then click Next.
17. On the Private Key page, ensure that Create a new private key is selected, and then click Next.
18. On the Cryptography for CA page, keep the default selections, and then click Next.
19. On the CA Name page, in the Common name for this CA text box, type Adatum-IssuingCA,
and then click Next.
20. On the Certificate Request page, ensure that Save a certificate request to file on the target
machine is selected, and then click Next.
23. On the Results page, ignore the warning messages, and then click Close.
1. On LON-DC1, in Server Manager, click Tools, and then click Group Policy Management.
2. In the Group Policy Management Console, expand Forest: Adatum.com, expand Domains,
expand Adatum.com, right-click Default Domain Policy, and then click Edit.
5. In the file name text box, type \\lon-svr1\C$,and then press Enter.
9. Close the Group Policy Management Editor and the Group Policy Management Console.
2. In the Virtual Machines list, right-click 20742B-LON-DC1, and then click Revert.