{"id":2221,"date":"2017-06-21T21:41:37","date_gmt":"2017-06-21T21:41:37","guid":{"rendered":"http:\/\/microsoftgeek.com\/?p=2221"},"modified":"2018-09-06T23:18:17","modified_gmt":"2018-09-06T23:18:17","slug":"how-to-install-root-certificate-authority-on-windows-server-2012","status":"publish","type":"post","link":"https:\/\/microsoftgeek.com\/?p=2221","title":{"rendered":"How to install Root Certificate Authority on Windows Server 2012"},"content":{"rendered":"<p>This guide will have two parts. The first one will be Installation and Configuration of Root Certificate Authority and the second one will be the post configuration settings.<\/p>\n<h4><strong>Installation of Root certificate Authority<\/strong><\/h4>\n<p>Open Server Manger, click on Add Roles and Features from the dashboard.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-547 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled19.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"810\" height=\"280\" \/><\/p>\n<p>Next select the Role based or feature based installation and click Next.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-548 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled25.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"789\" height=\"555\" \/><\/p>\n<p>On the next page, select the local server and click on Next.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-549 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled34.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"790\" height=\"557\" \/><\/p>\n<p>On the Next page, select the Active Directory Certificate services and click Next, also you will get a confirmation to Add the required features, select Add Features and move next.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-550 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled44.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"412\" height=\"434\" \/><\/p>\n<p>On the next page you will asked for installing the Role Services. In our demonstration, we will just be selecting Certificate Authority.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-551 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled62.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"787\" height=\"553\" \/><\/p>\n<p>Now you can move ahead by clicking the install button and the Role will be installed on the server.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-552 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled72.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"786\" height=\"556\" \/><\/p>\n<h4><strong>Configuration of Root certificate Authority<\/strong><\/h4>\n<p>Now that we are finished with the installation of the Root CA, we will have to do the basic configuration of the Certificate Authority so that we can start issuing certificates to the subordibate CA\u2019s or clients.<\/p>\n<p>Click on AD CS on the left hand side of the Server Manager screen and click on More as shown in the figure.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-553 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled82.png\" sizes=\"auto, (max-width: 814px) 100vw, 814px\" srcset=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled82.png 814w, http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled82-214x140.png 214w\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"814\" height=\"532\" \/><\/p>\n<p>Now click on the Configuration option.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-554 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled92.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"887\" height=\"488\" \/><\/p>\n<p>Specify the Administrator account that will be used to configure. in our demonstration, we will use local admin account of the machine.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-555 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled102.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"764\" height=\"559\" \/><\/p>\n<p>Select the Services that we are configuring, in our case we have only one, select Certificate Authority and click Next.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-556 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled113.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"756\" height=\"556\" \/><\/p>\n<p>Next you will be asked to select the type of CA, since we are not connected to the domain, the Enterprise CA option is automatically greyed out. So we will select Standalone CA.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-557 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled121.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"760\" height=\"558\" \/><\/p>\n<p>Next we want to select the Root CA.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-558 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled131.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"761\" height=\"557\" \/><\/p>\n<p>In the next step, we will create a New Private Key. You can import the Old private in case your old Root CA has crashed or something like that.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-559 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled141.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"760\" height=\"559\" \/><\/p>\n<p>We will select the defaults in the next page for the cryptographic provider, Key length as 2048, and hash algorithm as SHA1 as these are compatible with most devices.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-560 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled151.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"763\" height=\"556\" \/><\/p>\n<p>Next we will specify the name of the Root CA.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-561 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled161.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"765\" height=\"559\" \/><\/p>\n<p>On the next page, we want to select the Validity period. We will setting it 10 years and not the dedault 5 years as it is very common for the Root CA to have such a high value.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-562 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled171.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"762\" height=\"558\" \/><\/p>\n<p>Next page, we will leave the Database and Database log locations as default.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-563 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled181.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"764\" height=\"559\" \/><\/p>\n<p>Now you will be presented with the summary page with all the selections that you made. Click on Configure.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-564 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled191.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"761\" height=\"558\" \/><\/p>\n<p>You will mow be presented with the confirmation page.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-565 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled20.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"763\" height=\"559\" \/><\/p>\n<h4><strong>View the certficate<\/strong><\/h4>\n<p>Now that we are done with the configuration as well, let us see the certificate that the Root CA generated. Click on Tools from the Server Manager and select Certification Authority.<\/p>\n<p>On the new window, select the server and right click to select Properties.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-566 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled211.png\" sizes=\"auto, (max-width: 298px) 100vw, 298px\" srcset=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled211.png 298w, http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled211-110x96.png 110w\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"298\" height=\"261\" \/><\/p>\n<p>Now click on View certificate on the General tab.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-567 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled221.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"413\" height=\"541\" \/><\/p>\n<p>As you can see below that the certificate is self signed and is valid for 10 years as we specified during the configuration. You will be able to see the other configuration settings in the details tab. Feel free to explore.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-568 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled231.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"415\" height=\"524\" \/><\/p>\n<h4><strong>Post Configuration settings<\/strong><\/h4>\n<p>The following commands needs to be run in order to finish the configuration of the Root CA and should be run before any certificates are created.<\/p>\n<p>This command configures the domain that will be embedded in each certificate that is created by the Root CA.<\/p>\n<p><code>Certutil-setreg CA\\DSConfigDN CN=Configuration,DC=enterprisedaddy,DC=com<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-570 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled241.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"673\" height=\"159\" \/><\/p>\n<p>These two commands configure the time period that certificates issued from the Root CA will be valid. In this case, they are set to 5 years, half the time period of the root CA. This setting should be at least half of the root CA.<\/p>\n<p><code>Certutil -setreg CA\\ValidityPeriodUnits 5<br \/>\nCertutil -setreg CA\\ValidityPeriod \"Years\"<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-571 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled251.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"678\" height=\"315\" \/><\/p>\n<p>These two commands determine how long a CRL (Certificate Revocation List) is valid from. In this case this means that after 52 weeks the CRL will be recreated rather than being updated.<\/p>\n<p><code>Certutil-setreg CA\\CRLPeriodUnits 52<br \/>\nCertutil-setreg CA\\CRLPeriod \"Weeks\"<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-572 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled26.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"675\" height=\"333\" \/><\/p>\n<p>These two setting determine the overlap period for CRL\u2019s.<\/p>\n<p><code>Certutil-setreg CA\\CRLOverlapPeriodUnits 12<br \/>\nCertutil-setreg CA\\CRLOverlapPeriod \"Hours\"<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-573 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/02\/Untitled27.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"670\" height=\"292\" \/><\/p>\n<h4><strong>Publishing the CRL and finalising the root CA set up<\/strong><\/h4>\n<p>For this step you need to go to the properties of the Root CA and click on the Extensions tab. You will now have to add the AIA and CRL points for the Subordinate CA.<\/p>\n<p>First we will add the Authority information Access details. Select Extension and click on Add.<\/p>\n<p>Type the name of the SubCA, in our case it will be http:\/\/ED-SUBCA.enterprisedaddy.com and click on Insert. The final value should look like below:<\/p>\n<p>http:\/\/ED-SUBCA.enterprisedaddy.com\/certdata\/<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-601 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/03\/Untitled11.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"413\" height=\"542\" \/><\/p>\n<p>Next we will add the CRL point for the SubCA.<\/p>\n<p>Like done previously, you will have to select the CRL distribution point from the extensions and final value should like the below. Do not forget to add .crl extension at the end.<\/p>\n<p>And also be sure check the first two options as seen below.<\/p>\n<p>http:\/\/ED-SUBCA.enterprisedaddy.com\/certdata\/.crl<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-604 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/03\/Untitled22.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"413\" height=\"544\" \/><\/p>\n<p>Click on OK next, it will prompt a message asking you to start the Active Directory Certificate Services. Click on Yes.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-605 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/03\/Untitled31.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"494\" height=\"176\" \/><\/p>\n<p>By doing this step, we have made the Root CA aware of the Sub CA.<\/p>\n<p>Next we will be publishing the Revocation list. To do so, we need go to the Revoked certificates and Right Click &gt; All Tasks &gt; Publish.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-606 no-display appear\" src=\"http:\/\/www.enterprisedaddy.com\/wp-content\/uploads\/2015\/03\/Untitled41.png\" alt=\"How to install Root Certificate Authority on Windows Server 2012\" width=\"358\" height=\"200\" \/><\/p>\n<p>A pop comes up, select New CRL as this is the first one that we are publishing and click on OK.<\/p>\n<p>That\u2019s it! You have now successfully configured the Root CA to issue the certificates.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This guide will have two parts. The first one will be Installation and Configuration of Root Certificate Authority and the second one will be the post configuration settings. Installation of Root certificate Authority Open Server Manger, click on Add Roles and Features from the dashboard. Next select the Role based or feature based installation and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33,48],"tags":[],"class_list":["post-2221","post","type-post","status-publish","format-standard","hentry","category-sec-secops","category-microsoft-windows-server-2012"],"_links":{"self":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2221"}],"version-history":[{"count":1,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2221\/revisions"}],"predecessor-version":[{"id":2222,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=\/wp\/v2\/posts\/2221\/revisions\/2222"}],"wp:attachment":[{"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microsoftgeek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}