Microsoft private cloud series-certificate Configuration

Source: Internet
Author: User
  • For DC. contoso. com, add a Certificate Server. The Certificate Service may be used in subsequent operations. Therefore, we need to add a Certificate Server in this step.

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M02/4B/B6/wKiom1Qw4yyxdxEWAALW-P0eN_g793.jpg "style =" width: 500px; Height: 350px; "Title =" 58.png" width = "500" Height = "350" border = "0" hspace = "0" vspace = "0" alt = "wKiom1Qw4yyxdxEWAALW-P0eN_g793.jpg"/>

  • Select the role service as the Certificate Authority:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B8/wKioL1Qw42CRhPu-AAH5MNXAg4U010.jpg "style =" width: 500px; Height: 352px; "Title =" 59.png" width = "500" Height = "352" border = "0" hspace = "0" vspace = "0" alt = "wKioL1Qw42CRhPu-AAH5MNXAg4U010.jpg"/>

  • Then click the exclamation point to configure the Certificate Server:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B8/wKioL1Qw42HB4P-JAAHsuAhp5zM600.jpg "style =" width: 500px; Height: 365px; "Title =" 60.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wKioL1Qw42HB4P-JAAHsuAhp5zM600.jpg"/>

  • Configure the Certificate Authority:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B6/wKiom1Qw4y_jUfzFAAGd2YpNAoE223.jpg "style =" width: 500px; Height: 365px; "Title =" 61.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw4y_jufzfaagd2ypnaoe223.jpg"/>

  • Enterprise CA

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B8/wKioL1Qw42OwsAtjAAIvANlRs_Q148.jpg "style =" width: 500px; Height: 365px; "Title =" 62.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw42owsatjaaivanlrs_q148.jpg"/>

  • Specify the Root CA

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B6/wKiom1Qw4zLiEZyPAAIumyd6MvY511.jpg "style =" width: 500px; Height: 365px; "Title =" 63.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw4zliezypaaiumyd6mvy511.jpg"/>

  • Set to create a new private key:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B6/wKiom1Qw4zOzpJh_AAJkHqZFhqQ736.jpg "style =" width: 500px; Height: 365px; "Title =" 64.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw4zozpjh_aajkhqzfhqq736.jpg"/>

  • Use the following algorithm:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B8/wKioL1Qw42ezAWEpAAHcvwmnEe8725.jpg "style =" width: 500px; Height: 365px; "Title =" 65.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw42ezawepaahcvwmnee8725.jpg"/>

  • Specify the CA Name:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B6/wKiom1Qw4zWC_nAuAAI6odnFHUo609.jpg "style =" width: 500px; Height: pixel PX; "Title =" 66.png" width = "500" Height = "368" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw4zwc_nauaai6odnfhuo609.jpg"/>

  • Set the validity period to five years:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M02/4B/B8/wKioL1Qw42nTCDn6AAGvrP7ITB8776.jpg "style =" width: 500px; Height: 365px; "Title =" 67.png" width = "500" Height = "365" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw42ntcdn6aagvrp7itb8776.jpg"/>

  • Click Next to install the certificate service until the installation is successful.

  • On the server, we use MMC to add a local computer and apply for a certificate:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B8/wKioL1Qw55WCG0nFAAMYkPSIL24627.jpg "style =" width: 500px; Height: 388px; "Title =" 68.png" width = "500" Height = "388" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw55wcg0nfaamykpsil24627.jpg"/>

  • Select computer account]

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B8/wKioL1Qw55XRHI-zAACeBHR56bg235.jpg "style =" width: 500px; Height: 163px; "Title =" 69.png" width = "500" Height = "163" border = "0" hspace = "0" vspace = "0" alt = "wKioL1Qw55XRHI-zAACeBHR56bg235.jpg"/>

  • In the certificate-> individual, select all tasks-> apply for a new certificate:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B6/wKiom1Qw52OAP37rAAG3Cl16YR0046.jpg "style =" float: none; "Title =" 70.png" alt = "wkiom1qw52oap37raag3cl16yr0046.jpg"/>

  • Select an Active Directory registration policy:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B6/wKiom1Qw52ODAZY1AAFA_BW8QHc073.jpg "style =" width: 500px; Height: 362px; "Title =" 71.png" width = "500" Height = "362" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw52odazy1aafa_bw8qhc073.jpg"/>

  • Select a computer and register:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B8/wKioL1Qw55ahaCHVAAEay8OsSbA559.jpg "style =" width: 500px; Height: 362px; "Title =" 72.png" width = "500" Height = "362" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw55ahachvaaeay8ossba559.jpg"/>

  • We can see that below the certificate there are some certificates, one of which is issued by the CONTOSO-DC-CA:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B8/wKioL1Qw55jTSKTzAAZvoXNxYbI510.jpg "style =" width: 500px; Height: 248px; "Title =" 73.png" width = "500" Height = "248" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw55jtsktzaazvoxnxybi510.jpg"/>

  • Run certsrv. MSC and right-click the CONTOSO-DC-CA

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B6/wKiom1Qw52aABIyqAAFtD2JTPY8060.jpg "style =" width: 500px; Height: pixel PX; "Title =" 74.png" width = "500" Height = "347" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw52aabiyqaaftd2jtpy8060.jpg"/>

  • Select general and view the certificate:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M02/4B/B8/wKioL1Qw55mAjqDhAAG2kl5M-_U974.jpg "style =" float: none; "Title =" 75.png" alt = "wKioL1Qw55mAjqDhAAG2kl5M-_U974.jpg"/>

  • Select view certificate and copy to file:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M02/4B/B6/wKiom1Qw52fzBCQkAAHJueYdvAY098.jpg "style =" float: none; "Title =" 76.png" alt = "wkiom1qw52fzbcqkaahjueydvay098.jpg"/>

  • Then, go to the Trusted Root Certificate Authority to import the certificate:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B8/wKioL1Qw55uyGtwtAAJNrqv4DeI492.jpg "style =" width: 500px; Height: 403px; "Title =" 77.png" width = "500" Height = "403" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw55uygtwtaajnrqv4dei492.jpg"/>

We also set binding in IIS

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M00/4B/B6/wKiom1Qw52uxXH-FAAS5mkGffqI824.jpg "style =" width: 500px; Height: 342px; "Title =" 78.png" width = "500" Height = "342" border = "0" hspace = "0" vspace = "0" alt = "wKiom1Qw52uxXH-FAAS5mkGffqI824.jpg"/>

  • Edit the port and use the SSL Certificate node1.contoso. com:

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B8/wKioL1Qw557ReJWdAAEO3r_c7Zw398.jpg "style =" width: 500px; Height: 331px; "Title =" 79.png" width = "500" Height = "331" border = "0" hspace = "0" vspace = "0" alt = "wkiol1qw557re1_daaeo3r_c7zw398.jpg"/>

  • Perform the same operation on other websites. Finally, restart the IIS service to make the change take effect.

650) This. width = 650; "src =" http://s3.51cto.com/wyfs02/M01/4B/B6/wKiom1Qw52vjES1wAAEO3r_c7Zw459.jpg "style =" width: 500px; Height: 331px; "Title =" 80.png" width = "500" Height = "331" border = "0" hspace = "0" vspace = "0" alt = "wkiom1qw52vjes1waaeo3r_c7zw459.jpg"/>


Microsoft private cloud series-certificate Configuration

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.