Enterprise PKI for Lab/Test

Simranjit Singh 1 Reputation point
2020-10-15T10:13:11.85+00:00

I'm looking for some advise on building a MS PKI. The query I have is - do org build a enterprise PKI for Testing, and how is it integrated with Domain controller. What are the best practices for Test PKI

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,720 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fan Fan 15,291 Reputation points Microsoft Vendor
    2020-10-16T00:51:14.803+00:00

    Hi,

    I built 2 PKI environment in my lab .
    Single tier PKI with one Enterprise CA, you can configure the CA on the DCs or a member server if you have additional servers.
    Two tier PKI with one Offline Root CA and an Enterprise CA
    For how to build the PKI, you can refer to the following links (step by step) , which one to choose, that depends on your requirements :

    https://social.technet.microsoft.com/wiki/contents/articles/11750.adcs-step-by-step-guide-single-tier-pki-hierarchy-deployment.aspx

    https://social.technet.microsoft.com/wiki/contents/articles/15037.ad-cs-step-by-step-guide-two-tier-pki-hierarchy-deployment.aspx

    Best Regards,