Active Directory ® Certificate Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.

Slides:



Advertisements
Similar presentations
Internet Information Services 7.0 and Internet Information Services 7.5 Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Advertisements

Selecting the Right Network Access Protection (NAP) Architecture Infrastructure Planning and Design Published: June 2008 Updated: November 2011.
Windows® Deployment Services
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
Windows Server ® 2008 and Windows Server ® 2008 R2 Active Directory ® Domain Services Infrastructure Planning and Design Published: February 2008 Updated:
Microsoft ® System Center Configuration Manager 2007 R3 and Forefront ® Endpoint Protection Infrastructure Planning and Design Published: October 2008.
DirectAccess Infrastructure Planning and Design Published: October 2009 Updated: November 2011.
Deploying and Managing Active Directory Certificate Services
Microsoft ® Forefront ® Unified Access Gateway Infrastructure Planning and Design Published: December 2009 Updated: July 2010.
Certificates Last Updated: Aug 29, A certificate was originally created to bind a subject to the subject’s public key Intended to solve the key.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Chapter 9 Deploying IIS and Active Directory Certificate Services
Malware Response Infrastructure Planning and Design Published: February 2011 Updated: November 2011.
Windows Server ® 2008 Active Directory ® Domain Services Infrastructure Planning and Design Series Published: February 2008 Updated: July 2009.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: July 2010.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Understanding Active Directory
Chapter 11: Active Directory Certificate Services
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Microsoft ® Application Virtualization 4.5 Infrastructure Planning and Design Series.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Windows Server Virtualization Infrastructure Planning and Design Series.
Configuring Active Directory Certificate Services Lesson 13.
Microsoft ® Exchange Online— Evaluating Software-plus-Services Infrastructure Planning and Design Published: November 2008 Updated: October 2010.
Microsoft ® SharePoint ® Online— Evaluating Software-plus-Services Infrastructure Planning and Design Published: June 2009 Updated: October 2010.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: February 2010.
Terminal Services in Windows Server ® 2008 Infrastructure Planning and Design.
Windows ® Deployment Services Infrastructure Planning and Design Published: February 2008 Updated: January 2012.
Module 10: Designing an AD RMS Infrastructure in Windows Server 2008.
Windows Server ® Virtualization Infrastructure Planning and Design Published: November 2007 Updated: January 2012.
Microsoft ® Application Virtualization 4.6 Infrastructure Planning and Design Published: September 2008 Updated: November 2011.
Microsoft ® SQL Server ® 2008 and SQL Server 2008 R2 Infrastructure Planning and Design Published: February 2009 Updated: January 2012.
Microsoft ® System Center Operations Manager Infrastructure Planning and Design Published: November 2012.
Selecting the Right Network Access Protection Architecture
Microsoft ® System Center Operations Manager 2007 Infrastructure Planning and Design Published: June 2008 Updated: July 2010.
Deploying PKI Inside Microsoft The experience of Microsoft in deploying its own corporate PKI Published: December 2003.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
OFC 200 Microsoft Solution Accelerator for Intranets Scott Fynn Microsoft Consulting Services National Practices.
Windows ® User State Virtualization Infrastructure Planning and Design Published: August 2010.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Series.
Internet Information Services 7.0 Infrastructure Planning and Design Series.
Selecting the Right Virtualization Technology Infrastructure Planning and Design Published: November 2007 Updated: November 2011.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Windows Server ® 2008 File Services Infrastructure Planning and Design Published: October 2008 Updated: July 2009.
Microsoft ® System Center Service Manager Infrastructure Planning and Design Published: December 2010 Updated: April 2012.
Microsoft ® System Center Service Manager 2010 Infrastructure Planning and Design Published: December 2010.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Configuring Directory Certificate Services Lesson 13.
Microsoft ® Exchange Server 2010 with Service Pack 1 Infrastructure Planning and Design Published: December 2010 Updated: July 2011.
Microsoft ® System Center Data Protection Manager 2007 with Service Pack 1 Infrastructure Planning and Design Published: January 2009 Updated: July 2010.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: November 2009.
Microsoft ® Enterprise Desktop Virtualization Infrastructure Planning and Design Published: March 2009 Updated: November 2011.
Windows Server ® 2008 R2 Remote Desktop Services Infrastructure Planning and Design Published: July 2008 Updated: February 2011.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Windows Server ® 2008 and Windows Server 2008 R2 Print Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
1. 2 Overview In Exchange security is managed by assigning permissions in Active Directory Exchange objects are secured with DACL and ACEs Permissions.
Module 13: Enterprise PKI Active Directory Certificate Services (AD CS)
Microsoft ® System Center Virtual Machine Manager 2008 R2 Infrastructure Planning and Design Series Published: June 2008 Updated: September 2009.
Microsoft ® Forefront ™ Identity Manager 2010 Infrastructure Planning and Design Published: June 2010.
Dynamic Datacenter Infrastructure Planning and Design Published: April 2010 Updated: July 2010.
Planning Engagement Kickoff
Deployment Planning Services
Microsoft® System Center Virtual Machine Manager 2008
Office 365 FastTrack Planning Engagement Kickoff
Deployment Planning Services
Deployment Planning Services
Microsoft® System Center Configuration Manager 2007 SP1 with R2
Infrastructure Planning and Design
Presentation transcript:

Active Directory ® Certificate Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011

What Is IPD? Guidance that clarifies and streamlines the planning and design process for Microsoft ® infrastructure technologies IPD: Defines decision flow Describes decisions to be made Relates decisions and options for the business Frames additional questions for business understanding IPD guides are available at

Getting Started Active Directory Certificate Services

Purpose and Overview Purpose To provide design guidance for an Active Directory Certificate Services infrastructure Overview Active Directory Certificate Services architecture Active Directory Certificate Services infrastructure design process

What Is Active Directory Certificate Services? Active Directory Certificate Services (AD CS) provides a public key infrastructure (PKI) that can be used to distribute certificates from a trusted source to enable: Secure data transmission to a known recipient through encryption Signing of code and documents that confirms who the sender is and that the data has not been tampered with in any way

Active Directory Certificate Services Decision Flow SCMITA MAP w/ CAL Tracker

Active Directory Certificate Services Architecture SCMITA

Step 1: Identify the Certificate Requirements Task 1: Identify Where Certificates Will Be Used Record: Locations where certificates will be deployed Locations where certificates will be validated, which includes chaining-up and revocation checking

Validating with the Business (Step 1) Work with the business decision makers to ensure agreement and understanding of the certificate requirements. Ensure that the following questions are asked: Are there any additional legal, government, or regulatory requirements that may affect certificate usage? Are the implications of using certificates for encryption fully understood? These might include: Encrypted traffic cannot be inspected for malicious content Encryption and decryption will place an additional processing load on corporate servers The use of certificates and encryption increases complexity in the environment

Step 2: Design the Root Certification Authority Task 1: Determine the Number of Root CAs Start by planning for a single root CA Task 2: Determine the Root CA Type and Location The root CA can be deployed in one of the following ways: Stand-alone root CA Enterprise root CA External root CA

Step 3: Design the Certification Authority Hierarchy Task 1: Determine the Number of Issuing CAs Add CAs as necessary for the following reasons: Regulatory requirements Political and organizational reasons Low bandwidth locations Fault tolerance; can be achieved by the following techniques: Design additional CAs Make each CA highly available Task 2: Determine the Number of Intermediate CAs Intermediate CAs can optionally be added to the hierarchy design

Step 4: Design the Certification Authority Server Infrastructure Task 1: Design the Certificate Services Roles Decide which protocol will be used for each service Design and place the certificate services roles to meet the needs of all locations Task 2: Design the CA Servers Product group recommends each CA runs on a dedicated server Task 3: Design the IIS Servers IIS servers may be used to perform four different certificate services functions: Certificate enrollment Certificate validation CRL publication Online responder for OCSP

Summary and Conclusion The guide has addressed the technical aspects, service characteristics, and business requirements needed to complete a comprehensive review of the decision-making process. When used in conjunction with product documentation, this guide can help organizations confidently plan implementation of public key infrastructures using Active Directory Certificate Services Provide feedback to

Find More Information Download the full document and other IPD guides: Contact the IPD team: Access the Microsoft Solution Accelerators website:

Questions?

Addenda Benefits of Using the Active Directory Certificate Services Guide IPD in Microsoft Operations Framework 4.0 Active Directory Certificate Services in Microsoft Infrastructure Optimization

Benefits of Using the Active Directory Certificate Services Guide Benefits for Business Stakeholders/Decision Makers Most cost-effective design solution for implementation Alignment between the business and IT from the beginning of the design process to the end Benefits for Infrastructure Stakeholders/Decision Makers Authoritative guidance Business validation questions ensuring solution meets requirements of business and infrastructure stakeholders High integrity design criteria that includes product limitations Fault-tolerant infrastructure Infrastructure that’s sized appropriately for business requirements

Benefits of Using the Active Directory Certificate Services Guide (Continued) Benefits for Consultants or Partners Rapid readiness for consulting engagements Planning and design template to standardize design and peer reviews A “leave-behind” for pre- and post-sales visits to customer sites General classroom instruction/preparation Benefits for the Entire Organization Using the guide should result in a design that will be sized, configured, and appropriately placed to deliver a solution for achieving stated business requirements

IPD in Microsoft Operations Framework 4.0 Use MOF with IPD guides to ensure that people and process considerations are addressed when changes to an organization’s IT services are being planned.

Active Directory Certificate Services in Microsoft Infrastructure Optimization