03 active directory certificate services

26
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning , Microsoft Understanding Active Directory

Upload: gonzalo-santiago

Post on 26-Dec-2014

206 views

Category:

Education


6 download

DESCRIPTION

 

TRANSCRIPT

Page 1: 03 active directory certificate services

Christopher Chapman | MCTContent PM, Microsoft Learning, PDG Planning , Microsoft

Understanding Active Directory

Page 2: 03 active directory certificate services

Click to edit Master subtitle style

Microsoft Virtual Academy

Active Directory Certificate Services

(AD CS)

Page 3: 03 active directory certificate services

• What is AD CS?

• What does AD CS do/provide?

Module Overview

Page 4: 03 active directory certificate services

Module Overview

• Overview of Active Directory Certificate Services

• Understanding Active Directory Certificate Services Certificates

• Implementing Certificate Enrollment and Revocation

Page 5: 03 active directory certificate services

Lesson 1: Overview of Active Directory Certificate Services• What Is a Certification Authority?

• How CA Hierarchies Work

• Options for Implementing CAs

• Options for Integrating AD CS and AD DS

• Demonstration: Tools for Managing AD CS

Page 6: 03 active directory certificate services

What Is a Certification Authority?A Certification Authority (CA) is an entity entrusted to issue certificates to:

• Individuals• Computers• Organizations • Services

A Certification Authority (CA) is an entity entrusted to issue certificates to:

• Individuals• Computers• Organizations • Services

These certificates verify the identity and other attributes of the certificate subject to other entities

Page 7: 03 active directory certificate services

How CA Hierarchies Work

Reasons for deploying more than a single server CA hierarchy:

• Usage

• Organizational divisions

• Geographic divisions

• Load balancing

CA hierarchies include a root CA and one or more levels of subordinate CAsCA hierarchies include a root CA and one or more levels of subordinate CAs

• Restrict administrative access

• High availability

Page 8: 03 active directory certificate services

Options for Implementing Certification Authorities

When implementing a CA solution, you can: • Use an internal private CA

• Use an external public CA

Internal CAs are less expensive and provide more administrative options, but the issued certificates are not trusted by external clients

Page 9: 03 active directory certificate services

Enterprise Stand-Alone

Can use without AD DS X

Uses Group Policy for Trusted Root propagation X

Publishes certificates and CRL to AD DS X

Can enforce credential checks during enrollment X

Can have subject name generated automatically from logon credentials X

Can use certificate templates X

Can be used to generate smart card Windows domain authentication certificates

X

Can use certificate auto-enrollment X

Options for Integrating AD CS and AD DS

Page 10: 03 active directory certificate services

Demo: Tools for Managing AD CS

•Certification Authority

•Certificate Templates

•Online Responder

•Enterprise PKI

•Certificates

Page 11: 03 active directory certificate services

Lesson 2: Understanding Active Directory Certificate Services Certificates

• What Are Digital Certificates?

• How Public Keys and Private Keys Work

• Demonstration: Using Certificates to Secure Data

• What Are Certificate Templates?

Page 12: 03 active directory certificate services

What Are Digital Certificates?

A certificate is a digital file with two parts

• Base certificate information

• Public Key

• Public keys are distributed to all clients who request the key• Private keys are stored only on the computer from which the

certificate was requested

Page 13: 03 active directory certificate services

SSL (Encrypted)

Web Server

Web Client

Plaintext Plaintext

Different keys are used to encrypt and decrypt the message

Encrypt Decrypt

Private Key Public Key

How Public Keys and Private Keys Work

Page 14: 03 active directory certificate services

Demonstration: Using Certificates to Secure Data• In this demonstration, you will see how to use

certificates to secure data

Page 15: 03 active directory certificate services

What Are Certificate Templates?

Certificate templates:

• Define what certificates can be issued by the CAs

• Define certificates used for various purposes

• Define which security principals have permissions to read, enroll, and configure the certificate template

Page 16: 03 active directory certificate services

Lesson 3: Implementing Certificate Enrollment and Revocation• Options for Implementing Certificate Enrollment

• Demonstration: Using Web Enrollment to Obtain Certificates

• Administering Certificate Enrollment

• Demonstration: Administering Certificate Requests

• Options for Automating Certificate Enrollment

• What is Certificate Revocation?

• Demonstration: Revoking Certificates

Page 17: 03 active directory certificate services

Options for Implementing Certificate Enrollment

What methods are used for certificate enrollment?

• Web Enrollment

• Manual/Offline Enrollment

• Automatic Enrollment

Page 18: 03 active directory certificate services

Demo: Using Web Enrollment to Obtain Certificates• In this demonstration, you will see how to use Web

enrollment to obtain certificates

Page 19: 03 active directory certificate services

Administering Certificate EnrollmentTo obtain a certificate using manual enrollment:

Create a certificate request

Submit certificate request to CA

Obtain administrative approval for certificate

Retrieve certificate from CA and install on client

11

33

44

22

Page 20: 03 active directory certificate services

Demo: Administering Certificate Requests

• In this demonstration, you will see how to administer certificate requests

Page 21: 03 active directory certificate services

Domain Computer

Enterprise CA

Group Policy

Group Policy triggers automatic request

Auto-enroll is enabled on the template from which the requested certificate is created

Options for Automating Certificate Enrollment

Page 22: 03 active directory certificate services

What Is Certificate Revocation?

Clients can ensure the certificate has not been revoked by using the following methods:

• Online Certificate Status Protocol responder service (OCSP)

• Certificate Revocation Lists (CRLs)

Certificate revocation occurs when a certificate is invalidated before its expiration periodCertificate revocation occurs when a certificate is invalidated before its expiration period

Page 23: 03 active directory certificate services

Demonstration: Revoking Certificates

• In this demonstration, you will see how to revoke certificates

Page 24: 03 active directory certificate services

Module Review and Takeaways

• Review Questions

• Summary of AD CS

Page 25: 03 active directory certificate services

Thanks for Watching!

Page 26: 03 active directory certificate services

©2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Office, Azure, System Center, Dynamics and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.