Разворачиваем RCA (Microsoft PKI)

Описание к видео Разворачиваем RCA (Microsoft PKI)

Установка основного сервера выдачи сертификатов в иерархии PKI


Команды из видео:
notepad C:\Windows\CAPolicy.inf


[Version]
Signature=”$Windows NT$”
[PolicyStatementExtension]
Policies=InternalPolicy
[InternalPolicy]
OID= 1.2.3.4.1455.67.89.5
[Certsrv_Server]
RenewalKeyLength=4096
RenewalValidityPeriod=Years
RenewalValidityPeriodUnits=20
CRLPeriod=Years
CRLPeriodUnits=20
CRLDeltaPeriod=Days
CRLDeltaPeriodUnits=0
LoadDefaultTemplates=0

Define the Active Directory Configuration Partitions Distinguished Name.

certutil -setreg ca\DSConfigDN "CN=configuration,DC=HeavilyArmedNerd,DC=local"

certutil -setreg ca\DSDomain "DC=HeavilyArmedNerd,DC=local"



This will sets the overlap period between the CRL and the Delta CRL.
certutil.exe –setreg CA\CRLOverlapPeriodUnits 3

_______________________________________________________
This command will sets the CRL Overlap Period to weeks.
certutil.exe –setreg CA\CRLOverlapPeriod “Weeks”

_______________________________________________________
This command will sets the maximum certificate validity period of certificates issued by this.
CA
certutil.exe –setreg CA\ValidityPeriodUnits 10

net stop certsvc
net start certsvc

Комментарии

Информация по комментариям в разработке