Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » How to Install and configure Active Directory Certificate Services
  • screenshot 2020 03 14 at 22.47.56
    How to block apps from running in Windows Windows
  • media8
    How to create a Windows 11 Bootable USB drive Windows
  • FoneTool
    FoneTool is the best iPhone backup software Backup
  • Configure Synology DS923+ NAS for File Sharing
    How to Configure Synology DS923+ NAS for File Sharing [Part 2] Reviews
  • a3a5a8be58fa09468cd4f70d36869e98
    Restore AD Objects: How to restore deleted user accounts in Active Directory with Microsoft LDP and PowerShell Windows Server
  • image 38
    How to Fix “Unknown hard error” on Windows Server and Windows 10 Windows
  • Remote Desktop 2 1
    How to install RDS via Quick Start Deployment: Install, Publish, Update, and Uninstall Remote Desktop Web Client Web Server
  • Object First OOTBI   Best Storage Repo for Veeam
    Understanding User Roles & Access Control in Object First OOTBI Backup

How to Install and configure Active Directory Certificate Services

Posted on 28/01/202119/08/2025 Christian By Christian 2 Comments on How to Install and configure Active Directory Certificate Services

In this article, we shall discuss “How to Install and configure Active Directory Certificate Services”. Active Directory Certificate Services (AD DS) is used to create certification authority and related role services that allow you to issue and manage certificates. See the following interesting guides on how to import a certificate into the Trusted Root and Personal file certificate store, how to request a certificate signing request in Windows using Microsoft Management Console, and how to export a certificate in PFX format in Windows.

A certificate authority is also referred to as certification authority and it helps to issue digital certificates and authenticate the digital identities of computer systems. By this we mean, it helps certifies the ownership of a public key by the named subject of the certificate. One of the objectives is to make communication on the internet secure by playing a vital role in digital security.

Certificate authorities (CA) are a critical part of the internet communication and without it, transactions wouldn’t be secure and you will never be able to safely shop, or perform online banking.

Install the Active Directory Certificate Services

I will be walking you through the steps to set up a CA in your environment. We will need to add the Certificate Authority Role to the server.

  • Launch the Server Manager as shown below and
  • Click on Add Roles and Features as shown below.

This is just an information page. Usually, you should skip the “before you begin” page so it does not come up with anything you wish to install a role or a feature. When you are done and click on Next

This installation is a role based installation, therefore, we will be selecting role-based or feature-based installation. Click on Next to continue

Configure Server and Server Roles

On the Select destination server, if you have multiple servers, please select your desired server or local server you wish to install the CA unto. In my case, I have just one server in the pool and it is selected automatically by default.

In Select Server Roles, in Roles, select Active Directory Certificate Services.

Check Active directory Certificate service
Check Active directory Certificate service

Note: When you are prompted to add required features and click on “Add Features” as shown below.

Click on Next
Click on Next

You should be able to proceed now by clicking on Next.

Check AD CS and click on next

Configure Features

On the select features page, we do not have to do anything here except you environments demands a feature installation. Please click on Next to proceed.

Click on Next to proceed

Configure Active Directory Certificate Services (AD CS)

In Active Directory Certificate Services, read the provided information, and then click Next.

on AD CS click on next

Select Certification Services in the Role Services and click Next.

In the future, I will be installing other roles as displayed on this screen below. Kindly search through the blog for these articles.

Check Certificate authority and click on Next

Start Installation

Please select “Restart” the destination server automatically if required and click Yes in the popup. Lastly on this page, click Install.

Select restart destination server automatically if required. click Yes on the Pop-up and click on install

As you can see below, the installation has started and you can view the progress from this window.

Click on close to close window while installation is in progress
Click on close to close window while installation is in progress

Note: You can also click on the close button to have this window closed while the installed is still in progress.

You can close window while installation is in progress
You can close window while installation is in progress

Configure Active Directory Certificate Services (AD CS)

Usually, a new AD CS window will open up automatically for the post configuration of Active Directory Certificate Services (AD CS). If this is not the case, please click on the Server Manager

  • Click on the flag as shown below and
  • Click on “Configure Active Directory Certificate Services”
Click on "Configure Active Directory Certificate Services"

Select Destination Server

This will also open the AD CS window as shown below. Click on Next as I do not want to change the destination server

Click on Next

Select Certificate authority (CA)

As you can see, because other roles were not previously selected as roles services to install, they are automatically grayed out.

Check Certificate authority
Check Certificate authority
Click on Next
Click on Next

On the “Setup Type” page, select “Enterprise CA” , and then click “Next” to proceed.

Select Enterprise CA and click on next

On the Specify the type of the CA page, select Root CA, and then click Next.

Select Root CA and click on Next

Create New Private Key

While on the Specify the type of the private key page, select Create a new private key and then click Next.

Select create a new private key and click on next

Configure Cryptography for CA

On the Cryptography for CA page, keep the default settings for CSP (RSA#Microsoft Software Key Storage Provider) and the hash algorithm (SHA256), and determine the best key character length for your deployment.

Note: Large key character lengths provide optimal security; however, they can impact server performance and might not be compatible with legacy applications. It is recommended that you keep the default setting of 2048. Click Next.

Keep the default Cryptography setting and click on next

On the CA Name page, keep the suggested common name for the CA or change the name according to your requirements.

Ensure that you are certain the CA name is compatible with your naming conventions and purposes, because you cannot change the CA name after you have installed AD CS. Click on Next to continue the configuration.

Specify Validity Period

On the Validity Period page, in Specify the validity period, type your desired number and select a time value (Years, Months, Weeks, or Days). The default setting of five years. Click on Next to continue the configuration.

Select CA Database Location

On the CA Database page, in Specify the database locations, specify the folder location for the certificate database and the certificate database log.

If you specify locations other than the default locations, ensure that the folders are secured with access control lists (ACLs) that prevent unauthorized users or computers from accessing the CA database and log files. Click Next to continue the configuration.

Finally Configure Active Directory Certificate Services (AD CS)

Click Configure on the confirmation page as shown below.

That is all that needs to be done. Also if you would like to create AD DS via PowerShell. To access the certification authority, click on the Server Manager

Now, you can perform the following operation. Click on the see this guide on how to create certificate templates.

I hope you found this blog post on How to Install and configure Active Directory Certificate Services helpful. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Active Directory Certificate Services, Certificate Authority, Certificates, SSL, Windows 10, Windows Server 2016

Post navigation

Previous Post: An error occurred while trying to start the Windows deployment services error 0x906
Next Post: Create a certificate template for BitLocker Network Unlock

Related Posts

  • schedulepythontasksinWindows
    Run Python Script via Windows Task Scheduler Windows
  • Screenshot
    Change Active Directory Domain name from dot local to dot com Windows Server
  • screenshot 2020 04 27 at 13.30.17
    What are the differences between a Role and a Feature Windows Server
  • xyxc
    How to link a removable media to a Deployment Share: Replicate Deployment share to a removable device Windows Server
  • fix windows activation 0x87E10BC6 error
    Fix Error 0x87E10BC6 on a PC running Windows non-core Edition Windows
  • MBAM
    Fix MBAM Client Deployment is only supported on MBAM 2.5 SP1 Windows

More Related Articles

schedulepythontasksinWindows Run Python Script via Windows Task Scheduler Windows
Screenshot Change Active Directory Domain name from dot local to dot com Windows Server
screenshot 2020 04 27 at 13.30.17 What are the differences between a Role and a Feature Windows Server
xyxc How to link a removable media to a Deployment Share: Replicate Deployment share to a removable device Windows Server
fix windows activation 0x87E10BC6 error Fix Error 0x87E10BC6 on a PC running Windows non-core Edition Windows
MBAM Fix MBAM Client Deployment is only supported on MBAM 2.5 SP1 Windows

Comments (2) on “How to Install and configure Active Directory Certificate Services”

  1. Avatar photo No One says:
    06/03/2024 at 8:38 PM

    What about Microsoft’s recommendation for mitigating NTLM relay attacks on Active Directory Certificate Services (AD CS) – KB5005413?

    Log in to Reply
    1. chris Christian says:
      20/03/2024 at 6:45 PM

      Thank you for your feedback. We will create an article on this soon!

      Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • screenshot 2020 03 14 at 22.47.56
    How to block apps from running in Windows Windows
  • media8
    How to create a Windows 11 Bootable USB drive Windows
  • FoneTool
    FoneTool is the best iPhone backup software Backup
  • Configure Synology DS923+ NAS for File Sharing
    How to Configure Synology DS923+ NAS for File Sharing [Part 2] Reviews
  • a3a5a8be58fa09468cd4f70d36869e98
    Restore AD Objects: How to restore deleted user accounts in Active Directory with Microsoft LDP and PowerShell Windows Server
  • image 38
    How to Fix “Unknown hard error” on Windows Server and Windows 10 Windows
  • Remote Desktop 2 1
    How to install RDS via Quick Start Deployment: Install, Publish, Update, and Uninstall Remote Desktop Web Client Web Server
  • Object First OOTBI   Best Storage Repo for Veeam
    Understanding User Roles & Access Control in Object First OOTBI Backup

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,831 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.