Setting up a PKI
Now we have finished the theory part of this chapter and are moving on to the deployment part. In this section, I am going to demonstrate how we can set up a PKI using the two-tier model. I have used this model as it is the most commonly used model for medium and large organizations:
Figure 13.14: Planned PKI setup
The preceding diagram explains the setup I am going to configure. Here, I have one domain controller, one standalone root CA, and one issuing CA. All are running with Windows Server 2022 with the latest updates.
Setting up a standalone root CA
The first step is to set up the standalone root CA. This is not a domain member server and is operating on the workgroup level. Configuring it on a separate VLAN will add additional security to the root CA.
Once the server is ready, log in to the server as a member of the local administrator group. The first task is to install the AD CS role service. This can be done using the following command...