Windows AD Certificate Services Family---certificate use range (2)

Source: Internet
Author: User

Lab Environment:

LON-DC1 WINDOWS2012R2 Ad+ca

LON-CL1 Windows8.1 Domain Client +office2013

Lon-cl2 Windows8.1 Domain Client +office2013

Experimental Purpose:

Use a certificate for digital signatures



Experimental steps:

First, build enterprise CA


Log in to LON-DC1 using the domain Administrator account, open the PowerShell console on LON-DC1, enter Add-windowsfeature adcs-cert-authority,adcs-web-enrollment- Includemanagementtools

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/57/07/wKiom1SPmk-T_kQ9AAMlaz-uoA8785.jpg "title=" QQ picture 20141216091415.jpg "alt=" Wkiom1spmk-t_kq9aamlaz-uoa8785.jpg "/>

After the command is completed, we need to configure AD Certificate Services in Server Manager, in the top right-hand corner of Server Manager, there is an exclamation mark, and when you click the exclamation mark, the "Configure Active Directory Certificate Services on the destination server" appears.

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/57/07/wKioL1SPu5LBoQiBAAOQFLMQAo4528.jpg "title=" QQ picture 20141216101455.jpg "alt=" Wkiol1spu5lboqibaaoqflmqao4528.jpg "/>

After clicking Configure Certificate Services, a new window will appear, for example, we use the default option and click Next directly

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/57/09/wKiom1SPu3-z01hPAAPbK9mhWG8045.jpg "title=" QQ picture 20141216101517.jpg "alt=" Wkiom1spu3-z01hpaapbk9mhwg8045.jpg "/>

Next, you will be asked to select the role services you need to configure, the roles that are not installed in the first place cannot be checked here, because we have installed the role of certification authority and Web enrollment, so we can check these two options for the next configuration

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/07/wKioL1SPvEqSJhwzAAOPdI-OFmw472.jpg "title=" QQ picture 20141216101602.jpg "alt=" Wkiol1spveqsjhwzaaopdi-ofmw472.jpg "/>

Next we need to specify the CA's setting type because we are in a domain environment, so here the default enterprise CA is maintained

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/09/wKiom1SPvBTCxQiwAAQFi3sIsVk859.jpg "title=" QQ picture 20141216101626.jpg "alt=" Wkiom1spvbtcxqiwaaqfi3sisvk859.jpg "/>

After choosing a setting type, we need to set the CA type, where we use the default option root CA

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/07/wKioL1SPvSDROgSzAAQMkBoVo0s386.jpg "title=" QQ picture 20141216101640.jpg "alt=" Wkiol1spvsdrogszaaqmkbovo0s386.jpg "/>

All subsequent settings will remain the default, click Next, finally we can see the entire configuration summary, confirm that no errors or exceptions, directly click the Configuration button to start configuring Certificate Services

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/57/09/wKiom1SPvSmybfxnAAQvvTH0ENk322.jpg "title=" QQ picture 20141216101757.jpg "alt=" Wkiom1spvsmybfxnaaqvvth0enk322.jpg "/>

After successful configuration, you can see the following screen

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/57/09/wKiom1SPvXzDSHnLAANxo7lyMow361.jpg "title=" QQ picture 20141216101907.jpg "alt=" Wkiom1spvxzdshnlaanxo7lymow361.jpg "/>


Second, the client to apply for a user certificate


Log in to LON-CL1 with the User1 account and then run the MMC command to open the console, select File-Add/Remove Snap-in in the console-certificates-add-OK

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/04/wKioL1SPj9mShOrxAAXE1ndMznY570.jpg "title=" QQ picture 20141216094636.jpg "alt=" Wkiol1spj9mshorxaaxe1ndmzny570.jpg "/>

Expand the Add Certificates snap-in, right-select personal-All Tasks-Request New Certificate

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/57/06/wKiom1SPkByhiSpgAAUm2nvNFtc878.jpg "title=" QQ picture 20141216094917.jpg "alt=" Wkiom1spkbyhispgaaum2nvnftc878.jpg "/>

After you click Request a new certificate, the window that appears continues to click two times next, we can see the following screen

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/57/07/wKioL1SPvzGgweXyAAVgxO6BrSI596.jpg "title=" QQ picture 20141216130831.jpg "alt=" Wkiol1spvzggwexyaavgxo6brsi596.jpg "/>

We tick "user" and then click "Register", after successful registration as shown, then we will close this window and console

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/07/wKioL1SPwJ_xTXuKAAU7PjqdTyQ277.jpg "title=" QQ picture 20141216131439.jpg "alt=" Wkiol1spwj_xtxukaau7pjqdtyq277.jpg "/>


Third, digitally sign the Word document

Create a new Word file on LON-CL1, enter some content in Word and save

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/0B/wKioL1SP82yD_11qAAKj5W8585Q294.jpg "title=" QQ picture 20141216165123.jpg "alt=" Wkiol1sp82yd_11qaakj5w8585q294.jpg "/>

Open the Microsoft office signature line in the drop-down menu by selecting Insert in the Word's toolbar, and then selecting Signature Line

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/57/0E/wKiom1SP87jDFab7AAK0ETrtHhM904.jpg "title=" QQ picture 20141216165507.jpg "alt=" Wkiom1sp87jdfab7aak0etrthhm904.jpg "/>

Put the suggested signer, suggest the signer's title, email address to fill in the corresponding information, and then click "Confirm"

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/57/0E/wKiom1SP_1LTY0jpAAOvznUnd9I571.jpg "title=" QQ picture 20141216174448.jpg "alt=" Wkiom1sp_1lty0jpaaovznund9i571.jpg "/>

After you have set your signature, you can see that there is a signature icon in the inserted position, right click on the signature icon, select "Sign", sign the signature to the document

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/0C/wKioL1SQAezSpQLdAANJokofwXA444.jpg "title=" QQ picture 20141216175205.jpg "alt=" Wkiol1sqaezspqldaanjokofwxa444.jpg "/>

In the pop-up window, you can see a blank field on the right side of x, you can add your own personality picture or directly enter your specific content, here we use User1 to do examples, fill in, we click "Signature", then pop up the confirmation window directly OK

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/57/0E/wKiom1SQAdSRpPzRAAQMFdmbhKU112.jpg "title=" QQ picture 20141216175532.jpg "alt=" Wkiom1sqadsrppzraaqmfdmbhku112.jpg "/>

Once the signature is successful, the document is not modifiable and you can see that all the buttons for editing the contents of the document are grayed out in the Insert option.

650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/57/0C/wKioL1SQA0DRaxijAAKGC74rgDs480.jpg "title=" QQ picture 20141216175859.jpg "alt=" Wkiol1sqa0draxijaakgc74rgds480.jpg "/>







This article is from the "Dry Sea Sponge" blog, please be sure to keep this source http://thefallenheaven.blog.51cto.com/450907/1590789

Windows AD Certificate Services Family---certificate use range (2)

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.