August 2019
Intermediate to advanced
786 pages
20h 22m
English
Now we have a working PKI, and we can turn off the standalone root CA. It should only be brought online if the issuing CA certificates are expired or the PKI is compromised.
The CA comes with predefined Certificates Templates. These can be used to build custom certificate templates according to the organization's requirements and can be published to AD.
CA certificate templates are available under the Certificate Templates MMC. They can be accessed using Run | MMC | File | Add/Remove Snap-in... | Certificate Templates.
To create a custom template, right-click on a template and click on Duplicate Template:

This will open ...