Figure A: Select Active Directory Certificate Services role
You will see a screen to introduce Active Directory Certificate Services. Click Next , Windows will ask you about the component you want to install. At this point, select the Certification Authority and Certification Authority Web Enrollment options. Depending on how you configure the server, you will see a message indicating that you need to install some additional role services. If you receive this message, click the Add Required Role Services button .
Click Next , Windows will ask you if you want to create Standalone Certificate Authority or Enterprise Certificate Authority. Select the Enterprise option and click Next.
You should now see a message asking you to create a Root CA or a Subordinate CA. Since this is the first CA, you must select the Root CA option as shown in Figure B below.
Figure B: Select the Root CA option and click Next.
The next screen will ask if you want to create a new key or if you want to use an existing one. Since this is a completely new deployment, let's create a new key.
Click Next , Windows will ask you to configure encryption settings for CA. Click Next to accept the default values.
You will now be prompted to provide a name for CA. Although you can use the default values, the best way is to replace them with easy-to-remember names. For example, you can see in Figure C that we named our CA Lab2-CA.
Figure C: Choose a name that is easy to remember
Click Next , and you will see a prompt for the validity period for certificates issued by CA. The default value is 5 years, but you can adjust this parameter if you want.
Click Next , Windows will ask you to choose a location for the certificate database. It should be noted that what we mentioned above is important in protecting the certificate store. The thing to do here is to select a location where an automatic failover array exists if possible.
Depending on whether you are required to add the IIS role service to the server, the next screen you see may be an introduction of IIS. Click Next to move to the next screen.
You should now see a screen asking if you want to install additional role services. Because Windows automatically selects all required role services, you don't need to add any services, just click Next to continue.
You will then see a screen that summarizes the selected configuration options, as shown in Figure D. Verify that any information that appears is correct, and then click Install . When the installation is complete, click Close .
Figure D: Read through the configuration summary table to make sure everything is correct
Conclude
So far, we've shown you how to deploy an enterprise CA, which is when we can start building the rest of the infrastructure needed for wireless security. In the next part of this article series, I will show you how to enforce security based on PEAP.