Active Directory Certificate Services

Brian Svidergol, Vladimir Meloski, Byron Wright, Santos Martinez, Doug Bassett · 2018

This chapter discusses Active Directory Certificate Services (AD CS) as it exists today in Windows Server 2016. It focuses on the most relevant material that most admins must deal with when planning and implementing AD CS. Most new versions of Windows Server introduce new functionality for AD CS. AD CS is a public key infrastructure (PKI) solution for managing certificates in a network. The chapter looks at some of the operational aspects of managing a PKI. In large organizations, it is common to have the PKI owned by the information security team while the PKI is operated by a server administration team. Instead of requestors choosing the key length or whether a certificate's private key can be exported, a template dictates that information. In some organizations, auto-enrollment is used for client computers often in a scenario where client certificates are used for authentication, such as a secure wireless network.

Read the paper · More papers on PaperTik