This article describes in detail the installation and configuration of an Active Directory Certificate Server, which is allowed to be deployed in a domain or workgroup environment. In order to test the convenience of directly deploying Certificate Services on DCs, the environment should not install Certificate Services on DCs, it is strongly recommended that Certificate Services be deployed on a separate server.
1.1 Open Server Manager and click "Add Roles and Features"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/07/wKioL1WQCtGTu2-fAALJEo0xgyc982.jpg "title=" 1.png " alt= "Wkiol1wqctgtu2-faaljeo0xgyc982.jpg"/>
1.2 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/0A/wKiom1WQCRuDOZV6AAJqMCM-8rg820.jpg "title=" 2.png " alt= "Wkiom1wqcrudozv6aajqmcm-8rg820.jpg"/>
1.3 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/07/wKioL1WQCuXS2rMgAAIB0BIhtJE873.jpg "title=" 3.png " alt= "Wkiol1wqcuxs2rmgaaib0bihtje873.jpg"/>
1.4 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/0A/wKiom1WQCS_xwtx_AAKeJz9dBX8533.jpg "title=" 4.png " alt= "Wkiom1wqcs_xwtx_aakejz9dbx8533.jpg"/>
1.5 tick "Active Dicrectory Certificate Services"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/07/wKioL1WQCvjTObpcAALdtucv0XU115.jpg "title=" 5.png " alt= "Wkiol1wqcvjtobpcaaldtucv0xu115.jpg"/>
1.6 Leave the default, next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/0A/wKiom1WQCUKDkSFaAAL8E3QgLZc761.jpg "title=" 6.png " alt= "Wkiom1wqcukdksfaaal8e3qglzc761.jpg"/>
1.7 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/07/wKioL1WQCwvgvyJrAAJBdJjK7rE117.jpg "title=" 7.png " alt= "Wkiol1wqcwvgvyjraajbdjjk7re117.jpg"/>
1.8 Check "certification authority" and "certification authority Web enrollment"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/0A/wKiom1WQCVPxpQRtAAJD5eRdrNU964.jpg "title=" 8.png " alt= "Wkiom1wqcvpxpqrtaajd5erdrnu964.jpg"/>
1.9 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/07/wKioL1WQCyHRi8xpAALnNACEhpo808.jpg "title=" 9.png " alt= "Wkiol1wqcyhri8xpaalnnacehpo808.jpg"/>
1.10 Leave the default, next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/0A/wKiom1WQCXDzRma-AAK3LPfPOvA068.jpg "title=" 10.png "alt=" Wkiom1wqcxdzrma-aak3lpfpova068.jpg "/>
1.11 Click "Install"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/0A/wKiom1WQCXmQaZ9RAALdZ3nMrT8892.jpg "title=" 11.png "alt=" Wkiom1wqcxmqaz9raaldz3nmrt8892.jpg "/>
1.12 Click "Configure ActiveDirectory Certificate Services on the target server" after the installation is complete.
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/07/wKioL1WQC0KxSizJAALQ2CHTMvc765.jpg "title=" 12.png "alt=" Wkiol1wqc0kxsizjaalq2chtmvc765.jpg "/>
1.13 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/0A/wKiom1WQCYrBITNQAAISkuJ4-qw924.jpg "title=" 13.png "alt=" Wkiom1wqcyrbitnqaaiskuj4-qw924.jpg "/>
1.14 Check "certification Authority" and "certification authority Web enrollment", Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/07/wKioL1WQC1WibfVwAAHHBcJdx7s101.jpg "title=" 14.png "alt=" Wkiol1wqc1wibfvwaahhbcjdx7s101.jpg "/>
1.15 Select "Enterprise CA" and Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/0A/wKiom1WQCZ6ScD54AAJZU0G8hjA212.jpg "title=" 15.png "alt=" Wkiom1wqcz6scd54aajzu0g8hja212.jpg "/>
1.16 Select "Root CA" and next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/07/wKioL1WQC2iBR19gAAJHWc_IXCQ244.jpg "title=" 16.png "alt=" Wkiol1wqc2ibr19gaajhwc_ixcq244.jpg "/>
1.17 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/07/wKioL1WQC3LjWbrsAAJfzd4LsvI421.jpg "title=" 17.png "alt=" Wkiol1wqc3ljwbrsaajfzd4lsvi421.jpg "/>
1.18 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/0A/wKiom1WQCbvT9fhvAAIH4e_dBMY517.jpg "title=" 18.png "alt=" Wkiom1wqcbvt9fhvaaih4e_dbmy517.jpg "/>
1.19 Depending on the actual modification of the CA common name, next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/0A/wKiom1WQCcSxn9bBAAIqrb7q-fo973.jpg "title=" 19.png "alt=" Wkiom1wqccsxn9bbaaiqrb7q-fo973.jpg "/>
1.20 based on actual * * * validity, Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/07/wKioL1WQC43AJhRsAAHFniYM28o089.jpg "title=" 20.png "alt=" Wkiol1wqc43ajhrsaahfniym28o089.jpg "/>
1.21 Next
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/07/wKioL1WQC5Wh2udJAAGeCVl47pU542.jpg "title=" 21.png "alt=" Wkiol1wqc5wh2udjaagecvl47pu542.jpg "/>
1.22 Click "Configure"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/0A/wKiom1WQCd6Tk0aKAAJdPqUUe30764.jpg "title=" 22.png "alt=" Wkiom1wqcd6tk0akaajdpquue30764.jpg "/>
1.23 After the configuration is successful, click "Close"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/07/wKioL1WQC7PR_FJIAAGc9NUbRKQ663.jpg "title=" 23.png "alt=" Wkiol1wqc7pr_fjiaagc9nubrkq663.jpg "/>
1.24 in Server Manager, click "Tools"-"certification Authority"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/0A/wKiom1WQCgHgfPz_AAQ3D3RfMOE154.jpg "title=" 24.png "alt=" Wkiom1wqcghgfpz_aaq3d3rfmoe154.jpg "/>
1.25 Click "Huangjh-ca" right Button "properties"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/07/wKioL1WQC8yTGwlYAAHTh7HtiZg020.jpg "title=" 25.png "alt=" Wkiol1wqc8ytgwlyaahth7htizg020.jpg "/>
1.26 on the Extensions tab, follow the configuration and click "Apply"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/6F/0A/wKiom1WQCheR4_8_AAM53-Va6W8119.jpg "title=" 26.png "alt=" Wkiom1wqcher4_8_aam53-va6w8119.jpg "/>
1.27 Click "Yes"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/07/wKioL1WQC-SwXYeOAACu-0-0EZY544.jpg "title=" 27.png "alt=" Wkiol1wqc-swxyeoaacu-0-0ezy544.jpg "/>
1.28 Select the extension "AIA" and tick "include in the AIA extension of issued certificate"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/0A/wKiom1WQCi_yhGG-AAKd1KbRXs0612.jpg "title=" 28.png "alt=" Wkiom1wqci_yhgg-aakd1kbrxs0612.jpg "/>
1.29 Click "Yes"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/07/wKioL1WQC_yCd_L5AACx6i0NwKA683.jpg "title=" 29.png "alt=" Wkiol1wqc_ycd_l5aacx6i0nwka683.jpg "/>
1.30 Right-click "Revoked Certificates"-"All Tasks"-"publish"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/6F/0A/wKiom1WQCkazzHSgAAIjUhZUEc0006.jpg "title=" 30.png "alt=" Wkiom1wqckazzhsgaaijuhzuec0006.jpg "/>
1.31 Select "New CRL" and click "OK"
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/6F/0A/wKiom1WQClTQWsaFAAFCbWF9bMA961.jpg "title=" 31.png "alt=" Wkiom1wqcltqwsafaafcbwf9bma961.jpg "/>
This completes the installation and configuration of the entire Active Directory Certificate Server and requires a restart of the Certificate Server after the configuration is complete.
This article is from the "Bright Future" blog, make sure to keep this source http://stephen1991.blog.51cto.com/8959108/1668863
Installation and configuration of Active directory Certificate Services