Set up CA server
For users, various security technologies are mainly realized through certificates in practical applications, and certificates are issued by the authoritative certification body CA.
1. Find the role in the Server Manager, and then add the role
2. Others are default.
3. In addition to the default certificate authority, you also need to install the Certificate Authority web enrollment component, and click the "add required role Services" button in the open interface to install the iis role, so that users can use the browser to apply for certificates.
4. The installation type of CA is independent. If the CA set up on the domain control selects the enterprise, the enterprise root CA can only issue certificates to domain users.
5. Select "root CA" for CA type.
6. Select "New Private key" in setting "Private key". This is the private key of CA. CA must have a private key before you can issue a certificate.
7. The default private key creation method is used. The encryption algorithm uses RSA, the key length is 2048 bits, and the hash algorithm uses SHA1.
8. The default value is used for CA name
9. The CA validity period defaults to 5 years.
10. The location where the certificate database is stored is the default value.
11. The default value is used in the role selection service of web server
12. Start the installation after confirmation
13. After the installation is complete, the CA can be managed through the Certificate Authority in the Administrative tools
14. After restart, open an ie browser and type url "http://ip/certsrv"" to open the certificate application page.