Table of Contents
This updated guide examines Click: How to Configure Cawe in a Windows Server 2012 R2 Domain and organizes the essential facts, background, and practical takeaways in clear American English.
Part 1of 3:
Installing and Configuring Computer, Domain, and Network Requirements
- Install and configure computer requirements.
- Install Windows 7 Virtual Machine.
- Change the Windows 7 Virtual Machine name tow7a15.
- Install Windows Server 2012 R2 Virtual Machine.
- Change the server name tow12r2a10and set password toPassworda10.
- Configure the network requirements.
- Computer name, IP address, subnet mask, preferred DNS
- w12r2a10,172.16.150.10,255.255.255.0,172.16.150.10
- W7a15,172.16.150.15,255.255.255.0,172.16.150.10
- Verify a successful ping of w12r2a10 and w7a15 in both directions.
- Install and configure domain requirements.
- Install AD DS and configure w12r2a10 to host domainkim.com.
- Install and configure AD CS with certificate services with default settings.
- Install and configure Web Server (IIS) role with default settings.
- Display, on w7a15, kim.com homepage by FQDN, http://w12r2a10.kim.com.
- Verify you cannot display securely, on w7a15, kim.com domain homepage by FQDN, https://w12r2a10.kim.com.
Part 2of 3:
Configuring Webserver Requirements
- Configure SSL properties.
- Go to "Administrative Tools" and click "IIS Manager," on w12r2a10.
- Expand "Sites."
- Click "Default Web Site."
- Double click SSL, in the center pane, to display the SSL Settings menu that has an SSL checkbox and three radio buttons labeledIgnore,Accept, andRequire.
- Notice that Require SSL is unchecked and Ignore is selected; these are the default settings after configuring SSL Bindings.
- Verify you cannot display, on w7a15, kim.com domain homepage by FQDN, https://w12r2a10.kim.com.
- Verify that kim-W12R2A10-CA is not listed in "IE Trusted Root Certification Authority."
- Verify that Personal does not have a certificate issued by domain kim.com.
- Verify the webserver configuration.
- Note that for a domain user to request a certificate when using a client that is not a domain member, you must create a special CA site, which is placed in the Sites branch in IIS manager and is given the name certsrv.
- Go to "Administrative Tools" and click "IIS Manager," on w12r2a10.
- Expand w12r2a10 (KIM...).
- Expand "Sites."
- Click "Default Web Site."
- Notice that certsrv is not listed; therefore, you must add AD CS feature, (CAWE) Role Service.
- Install CAWE.
- Go to "Server Manager" on w12r2a10.
- Click "Add Roles" and features to display "Add Roles and Features Wizard," before you begin..
- ClickNextto display "Select installation type."
- Notice that role-base or feature-base is selected.
- ClickNextto display "Select destination server."
- Notice that there is only one server, so there is nothing to select.
- ClickNextto display "Select server roles."
- Click the triangle next to ADCS to expand it.
- Click the checkbox next to Certification Authority Web Enrollment (CWE).
- Click "Add Required Role Services," when prompted.
- ClickNext, until "Install" is shown.
- ClickInstall.
- Leave the Installation progress open.
- Hover the progress bar to see when the install completes, 100%.
- Configure CAWE installation.
- Click Configure ADCS on the destination server to configure the service and display "Credentials."
- ClickNextto display "Role Services."
- Click the box next to "Certification Authority Web Enrollment."
- ClickNextto display the confirmation page.
- ClickConfigure.
- ClickCloseuntil you are returned to "Server Manager."
- Verify the webserver updated configuration.
- Expand "Sites" in IIS manager.
- Click "Default Web Site" and notice that certsrv is listed.
- Request and install certificate.
- Log on to w7a15 as maya.
- Go IE and on W7a15.
- Type https://w12r2a10.kim.com/certsrv.
- ClickContinue to this website (not recommended)when prompted with "This CA is not trusted."
- Typekimmaya Password01at the Windows Security prompt.
- Click Request a certificate at the "Microsoft Active Directory Certificate Services - kim-w12r2a10-CA" prompt.
- Click "Advanced Certificate Request."
- ClickCreateand submit a request to this CA.
- When prompted with Web access confirmation, click Yes.
- ClickSubmiton "Advanced Certificate Request."
- ClickYeswhen prompted with Web access confirmation.
- ClickInstall this certificate.
- ClickInstall this CA certificate.
- Click when prompted with "Do you want to open or save this file?"
- ClickAllowwhen prompted with "A website wants to open web content…"
- ClickInstall Certificatewhen prompted with "Certificate Information."
- ClickNexton "Welcome to the Certificate Import Wizard."
- Click onCertificate Store display, the radio button next to "Place all certificates in the following store."
- ClickBrowse.
- ClickTrusted Root Certification Authoritieson "Select Certificate Store."
- ClickOK.
- ClickYeson "Security Warning."
- ClickNext.
- ClickFinish.
- ClickYeswhen prompted with "Security Warning. You are about to install a certificate…"
- ClickOKon "Certificate Import Wizard."
- ClickOKon "Certificate Information."
- ClickInstall Certificateon "Certificate Issued."
- Terminate IE when your new certificate has been successfully installed.
Part 3of 3:
Verifying CAWE installation and Configuration
- You'll now want to test homepage with HTTP and HTTPS.
- Start IE on w7a15.
- Verify there is a Trusted Root Certification Authority for kim-W12R2A10-CA.
- View Issued Certificates, on w12r2a10, and notice that the Requester Name for this newly acquired certificate is KIMmaya.
- Log on to w7a15 as maya.
- Change the IE homepage on w7a15 to point to https://w12r2a10.kim.com.
- Terminate IE.
- Start IE and be sure the displayed page is using https, not http.
- Log on to w7a15 as andi.
- Change the home page to https://w12r2a10.kim.com.
- Verify that user andi cannot display https homepage.
- Log off as user andi.
- Log on as user maya.
- Verify that user maya can still display the https homepage.
FAQ
What is Click: How to Configure Cawe in a Windows Server 2012 R2 Domain about?
It provides a structured overview of click, explains the main context, and highlights practical takeaways for readers.
Why does this topic matter?
Understanding the main concepts helps readers evaluate the issue, avoid common mistakes, and make better-informed decisions.
How should readers use this information?
Use the guidance as a practical starting point, confirm details that may have changed, and follow current product, safety, or security recommendations.
Reader Comments 0
Sign in with email or Google to join the discussion.