Now we have finished the theory part of this chapter and are moving on to the deployment part. In this section, I am going to demonstrate how we can set up a PKI using the two-tier model. I have used this model as it is the most commonly used model for medium and large organizations:
The preceding diagram explains the setup I am going to configure. In it, I have one domain controller, one standalone root CA, and one issuing CA. All are running with Windows Server 2016 with the latest patch level.