Install and Configure AD CS Flashcards
How do you install Active Directory Certificate Services?
Through the Add Roles and Features wizard in Server Manager via the AD CS role.
What are the requirements to install an Active Directory Integrated CA?
- Must have AD CS role installed.
- Host must be domain-joined.
- User must be a member of Enterprise Admins group.
How do you install an AD Integrated CA?
- Install AD CS role
2. Within AD CS Config wizard, choose Enterprise CA on CA Type screen.
What are the requirements to install a standalone CA?
- Must have AD CS role installed.
2. User must be a member of Local Administrator group
When setting a root and subordinate CA structure, which CA type is preferred, Enterprise or Standalone?
Standalone
What management tool is used to manage CAs?
Certification Authority
How do you update the CRL?
Within CA tool, with the root CA selected, right click on Revoked Certificates and select All Tasks > Publish
A Publish CRL pop-up box will appear to create a new CRL, select New CRL > Ok
How do you install a subordinate CA?
- Install the AD CS role and CA Web Enrollment role service
- Within the AD CS Config wizard, specify Subordinate CA
- Move recently created Certificate request to a network share to be grabbed by Root CA server
- On Root CA server within AD CS, submit new certificate request and issue when complete
- Copy Issued Certificate to a file and place on network share to be reached by subordinate CA server
- Install Security Cert and CA Cert (from File Explorer and AD CS respectively)
- Create Public Key Infrastructure in a network share on the subordinate CA server
- Create Web Server utilizing IIS Manager
- Create forward lookup zone of web site (pki.domain.com)
- Within Certification Authority on subordinate CA server, start service
How do you install Online Responder?
On a member server, install the AD CS Online Responder role
How do you implement administrative role separation?
Security groups can be assigned CA permissions within AD CS to fulfill role separation.
How do you perform a back up of the CA?
Within Certification Authority, right click on CA server and select All Tasks > Back up CA
How do you perform a restore of the CA?
Within Certification Authority, right click on CA server and select All Tasks > Restore CA