module 13: enterprise pki active directory certificate services (ad cs)

8
Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Upload: shanon-lester

Post on 18-Jan-2016

233 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Module 13:Enterprise PKI Active Directory Certificate

Services (AD CS)

Page 2: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Lesson 1: Certificate Authority

List improvements to Certificate Services

Monitor Active Directory Certificate Services using PKIView

Describe new Group Policy settings for Certificate Services

Describe the Microsoft Simple Certificate Enrollment Protocol

Describe the Online Certificate Status Protocol

Use Certificate Web Enrollment

Page 3: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Manageability:

Improved administrative user experience

Network Device Enrollment

Service

Enabling delegated enrollment agent

functionality

Certificate Authority

Page 4: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Enterprise PKI

• Enhanced credential

life cycle management

• Enabling revocation

across all applications

• Enhanced manageability

and deployment of

Certificate Services

• New certificate

enrollment API and UI

Page 5: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Certificate Policy Settings

Central Certificate Setting Management

Computer Configuration\Windows Settings\Security Settings\Public Key Policies

Control Whether Users Make Peer Trust Decisions

Certificate Deployment

Page 6: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Microsoft Simple Certificate Enrollment Protocol

Generates One-Time Enrollment Passwords

Processes SCEP Enrollment Requests

Retrieves Pending Requests from certificate authority (CA)

Page 7: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Online Certificate Status Protocol

•Responder Features:–Support for multiple CAs

–Supports caching

–Supports NONCE and No-NONCE requests

•New Revocation Services:–New OCSP client in Windows Vista™

–New OCSP Responder in Windows Server® 2008

–Integrate OCSP stapling into Kerberos and SSL protocols

Page 8: Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)

Certificate Web Enrollment

Provides Certificates for Non-Domain Users

Based on CertEnroll.dll

Creates “CertSrv” Web Site.