June 2017
Beginner to intermediate
742 pages
18h 29m
English
The first step is to set up the stand-alone root CA. This is not a domain member server, and it is operating in the workgroup level. By configuring it on separate VLAN will add additional security to the root CA, as it will not be able to talk to each other directly even if it is online.
Once the server is ready, log into the server as the member of local administrator group. The first task is to install the AD CS role service. It can be done using the following command:
Add-WindowsFeature ADCS-Cert-Authority -IncludeManagementTools
Once the role service is installed, the next step is to configure the role and get the CA up and running:
Install-ADcsCertificationAuthority -CACommonName "REBELAdmin Root CA" ...