Skip to Content Information Center
Markvision Enterprise

Installing the subordinate CA server

  1. From the server, log in as a CAAdmin domain user.

  2. From Server Manager, click Manage > Add Roles and Feature.

  3. Click Server Roles, select Active Directory Certificate Services and all its features, and then click Next.

  4. From the AD CS Role Services section, select Certification Authority and Certificate Authority Web Enrollment, and then click Next.

    Note:  Make sure that all the features of Certificate Authority Web Enrollment are added.

  5. From the Web Server Role (IIS) Role Services section, retain the default settings.

  6. After installation, click Configure Active Directory Certificate Services on the destination server.

  7. From the Role Services section, select Certification Authority and Certificate Authority Web Enrollment, and then click Next.

  8. From the Setup Type section, select Enterprise CA, and then click Next.

  9. From the CA Type section, select Subordinate CA, and then click Next.

  10. Select Create a new private key, and then click Next.

  11. From the Select a cryptographer provider menu, select RSA#Microsoft Software Key Storage Provider.

  12. From the Key length menu, select 4096.

  13. In the hash algorithm list, select SHA512, and then click Next.

  14. In the Common name for this CA field, type the host server name.

  15. In the Distinguished name suffix field, type the domain component.

      Sample CA name configuration

    • Machine Fully Qualified Domain Name (FQDN): test.dev.lexmark.com
    • Common Name (CN): TEST
    • Distinguished name suffix: DC=DEV,DC=LEXMARK,DC=COM
  16. In the Certificate Request dialog box, save the request file, and then click Next.

  17. Do not change anything in the database locations window.

  18. Complete the installation.

  19. Sign the CA request of the root CA, and then export the signed certificate in PKCS7 format.

  20. From the subordinate CA, open Certification Authority.

  21. From the left panel, right‑click the CA, and then click All Tasks > Install CA Certificate.

  22. Select the signed certificate, and then start the CA service.

이 문서가 유용했습니까?
Top