Issuing CA Setup
VM Information
Section titled “VM Information”| Setting | Value |
|---|---|
| VM ID | 311 |
| Hostname | srv-ica-zrh-01 |
| IP | 10.30.30.21 |
| OS | Windows Server 2025 |
| Domain | corp.microsoftlab.ch |
Prerequisites
Section titled “Prerequisites”- Root CA installed and configured
- Root CA certificate and CRL published to PKI repositories
- PKI Web repositories operational
- DNS record pki.microsoftlab.ch resolving
Network Configuration
Section titled “Network Configuration”New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 10.30.30.21 -PrefixLength 24 -DefaultGateway 10.30.30.1Set-DnsClientServerAddress -InterfaceAlias "Ethernet" -ServerAddresses 10.30.30.15Add-Computer -DomainName "corp.microsoftlab.ch" -NewName "srv-ica-zrh-01" -Credential (Get-Credential "CORP\Administrator") -RestartCAPolicy.inf
Section titled “CAPolicy.inf”Create C:\Windows\CAPolicy.inf BEFORE installing AD CS:
[Version]Signature="$Windows NT$"
[PolicyStatementExtension]Policies=InternalPolicy
[InternalPolicy]OID=1.2.3.4.5.6.7.8.9.10Notice="MicrosoftLab Issuing CA - Internal Use Only"
[Certsrv_Server]RenewalKeyLength=3072RenewalValidityPeriod=YearsRenewalValidityPeriodUnits=5CRLPeriod=DaysCRLPeriodUnits=7CRLDeltaPeriod=DaysCRLDeltaPeriodUnits=1LoadDefaultTemplates=0
[CRLDistributionPoint]URL=http://pki.microsoftlab.ch/crl/%3%8%9.crl
[AuthorityInformationAccess]URL=http://pki.microsoftlab.ch/aia/%3%4.crtAD CS Installation
Section titled “AD CS Installation”# Install roleInstall-WindowsFeature AD-Certificate -IncludeManagementTools
# Configure Issuing CA (creates certificate request)Install-AdcsCertificationAuthority ` -CAType EnterpriseSubordinateCA ` -CACommonName "MicrosoftLab Issuing CA 01" ` -KeyLength 3072 ` -HashAlgorithmName SHA256 ` -CryptoProviderName "RSA#Microsoft Software Key Storage Provider" ` -ForceNote: This creates a certificate request file. CA service will NOT start until certificate is signed and installed.
Sign Certificate on Root CA
Section titled “Sign Certificate on Root CA”- Start Root CA VM (srv-rca-zrh-01)
- Copy request file to Root CA
- Submit and issue:
# Via GUI: certsrv.msc# 1. Right-click CA → All Tasks → Submit new request# 2. Select request file# 3. Pending Requests → Right-click → Issue# 4. Issued Certificates → Export as .cer- Copy signed certificate back to Issuing CA
- Shutdown Root CA
Install Signed Certificate
Section titled “Install Signed Certificate”certutil -installcert "C:\path\to\signed.cer"Start-Service CertSvcStatus
Section titled “Status”Note: Issuing CA setup is in progress. Certificate signing step pending.