Generating and Installing Domain Controller Certificate
Generating and Installing Domain Controller Certificate
Generating and Installing Domain Controller Certificate
Accurate as of 3/17/2017 using Microsoft 2012 Server Standard Edition for Certification Authority and Domain
Controller servers.
Use Case: Would like to use a local Enterprise Microsoft Certification Authority (CA) to issue a Domain Controller
(DC) certificate to the DC server. The DC server must have a certificate installed with the appropriate fields/values
as a pre-requisite to enabling PIV credential login for domain connected devices.
Install CA Role
1. Log on to the CA server as a member of the Enterprise Administrators group.
2. Open Server Manager
3. Click Manage, and then click Add Roles and Features.
4. Proceed through the Add Roles and Features Wizard, choosing the following options:
a. Server Roles: Active Directory Certificate Services
b. AD CS Roles Services: Certification Authority
5. On the Results page, click Configure Active Directory Certificate Services on the destination server.
6. Proceed through the AD CS Configuration, choosing the following options as necessary:
a. Role Service: Certification Authority
b. Setup Type: Enterprise CA
c. CA Type: Root CA
d. Private Key: Create a new private key
e. Cryptography: RSA#Microsoft Software Key Storage Provider, 2048 bit, SHA-256
f. CA Name:
i. Recommended naming convention
1. dc=[AD suffix], dc=[AD domain], cn=[certification authority name]
a. e.g. dc=gov, dc=[AgencyName], cn=[AgencyName] NPE CA1
g. Validity Period: 6 years
h. Certificate Database: <your preference>