June 2017
Beginner to intermediate
742 pages
18h 29m
English
Now, we have the working PKI, and we can turn off the stand-alone root CA. It should only be brought online if the issuing CA certificates are expired or PKI is compromised to generate new certificates.
Once the CA is ready, then objects and services can be used for certificates. The CA comes with the predefined Certificates Templates. These can be used to build custom certificate templates according to the organization requirements and publish it to AD.
The Certificate Templates MMC can be accessed using Run | MMC | File | Add/Remove Snap-in... | Certificate Templates.
To create a custom template, right-click on a template and click on Duplicate Template:
Then, it will open up the properties window and can change the ...