
Learn public key infrastructure basics and cryptography with hands-on PKI configuration, certificate services, and certificate-based website security. Benefit from a Microsoft official curriculum structure and practical troubleshooting.
Learn how public key infrastructure protects data and communications through encryption, hashing, confidentiality, and digital certificates. Explore PKI components like public and private keys, digital signatures, certificates, and CA-based availability.
Discover how PKI uses certificates for client-server authentication, https web traffic, software and driver signing, and email signing, with examples like PayPal and ADFS.
Explore the essential components of a PKI infrastructure, including the certification authority, root and subordinate CAs, certificate templates, CRLs and online responders, and AIA and CDP locations.
Understand what a digital certificate is, including issuer and subject, and how certificate extensions support PKI. See how root CAs and Verisign and PayPal illustrate certificate paths and trust.
Explore how cryptography protects data with encryption and digital signatures, and see the evolution from medieval seals to the enigma machine and Alice and Bob's substitution.
Learn how symmetric and asymmetric encryption protect data using shared and public keys, private keys, and certificates, including how symmetric keys are encrypted with public keys for secure transmission.
Explore how digital signatures verify the author, sign data with a private key, and rely on a hash value and public key to confirm integrity, certificates from a certification authority.
Explore encryption algorithms like DES, Triple DES, RSA, Blowfish, and AES, detailing block sizes, key lengths, and the hybrid use of symmetric keys with public key encryption.
Explore the evolution of hashing algorithms from MD5 to SHA-2, noting MD5's 128-bit hash, SHA-0/SHA-1's 168-bit hashes, SHA-1 deprecation, and the relatively limited adoption of SHA-3.
Explore the Windows Server certificate authority service, including root, private, public, and enterprise CAs, certificate issuance, revocation with CRLs and online responders, and NDES for devices.
Compare public and private certificate authorities, noting how private CAs issue certificates for internal users and devices, while public CAs secure internet-facing apps, with cost, trust, and auto enrollment.
Explain root and subordinate CAs in a PKI hierarchy, including self-signed root certificates, root-to-subordinate issuance, and policies by geography and service for large enterprises.
Compare standalone and enterprise CAs on Windows Server. Learn offline root CAs, subordinate CAs, domain integration, and templates for automatic certificate enrollment in a PKI infrastructure.
Explore implementing a public key infrastructure with root and subordinate CAs, covering CSP vs KSP, key lengths, hashing algorithms, certificate lifetimes, and enterprise deployment considerations.
Install a standalone root certification authority on Windows Server 2012 R2 and set up a subordinate CA in a two-tier hierarchy, in workgroup and domain contexts.
Install an enterprise subordinate certificate authority linked to the root CA. Configure web enrollment and publish CDP and AIA locations to enable certificate issuance for users and computers.
Enroll for certificates from a certificate authority, whether internal or external, and access various enrollment methods. Use certificates to encrypt files and secure websites with https.
Explore certificate templates in a certification authority, learn how templates define certificate format, deployment, and enrollment permissions, and how to duplicate and modify templates for versioned cryptography and auto enrollment.
Discover various certificate enrollment types, from web enrollment to offline requests, and learn how domain and non-domain clients request certificates via certificate authorities, management consoles, and auto enrollment policies.
Learn how to request a certificate via web enrollment through the IIS virtual directory, secured by HTTPS, including pending requests and certificate chain download.
Request a certificate using the MMC console by configuring trusted root and intermediate certificates, importing the certificate chain via web enrollment, and selecting the appropriate user or computer template.
Explore auto enrolment for certificate requests in large enterprises, enabling domain-joined clients to automatically enroll through a predefined certificate template, with group policy and CA configuration.
Generate an offline certificate request and submit it to a certificate authority to obtain and import a certificate on a client, using a policy file with certreq.
Learn to secure a website with a certificate by enabling https, using public and private keys to encrypt data, and bind the certificate to a domain on port 443.
Encrypt a file on disk with a certificate’s public key and decrypt with the private key, by importing the recipient’s public key via Active Directory and Encrypting file system.
Configure role-based access control for the certification authority, delegating admin tasks to the C administrator, cert manager, and backup operator; set CAA policy, CDP and URL extensions, and certificate revocation.
Configure CA policy and exit modules to control certificate requests and post issuance actions. Enterprise CA automatically issues with credentials validated by Active Directory, while standalone queues pending requests.
Explore how certificate revocation lists (CRLs) and delta CRLs support revocation checks, how CDP distribution points and AIA extensions help clients fetch revocation data, and how LDAP locations ensure accessibility.
Configure AIA and CDP extensions on the subordinate CA, enable HTTP publication for the CDP, publish URLs to LDAP/AD, and verify reachability to ensure issued certificates include accessible locations.
Explore new roles in certificate services introduced in Windows server 2008 onward, including network device enrollment service for Windows CE devices and certificate enrollment policies with OCSP support.
Learn how network device enrollment using NDES enables non-domain devices to obtain certificates from a certificate authority by generating keys, using SCMP, and submitting RA requests.
Learn how to install the NDC role on Windows Server 2012 R2, configure prerequisites, and assign necessary permissions for enterprise admins, service accounts, and certificate templates in a multi-server setup.
Configure the NDS server role under Active Directory Certificate Services on a dedicated box with a domain admin. Configure certificate templates, enrollment passwords, and SPN/DNS registration for device issuance.
Explore how certificate enrollment policy (CEP) and certificate enrollment service (CES) enable policy-based PKI enrollment, including domain joined and non-domain joined clients, via AD, LDAP, and HTTPS.
Configure certificate enrollment policy and certificate enrollment services to support non-domain clients behind firewalls, and set up CA, IIS, authentication, templates, and SSL for issuing certificates.
Explains online responder (OCSP), a c service that offloads certificate revocation checks from clients to a server, using caching, CDP/CRL lookups, and signed responses.
Configure an online responder (OCSP) by setting up the certificate template with enroll permissions and embedding the CSP URL via CAA extension, then install CSP server and test OCSP URL.
Install the root certificate authority and subordinate CA on Windows Server 2016 using Active Directory Certificate Services, configure a standalone CA, create a private key, and select the hashing algorithm.
Install the enterprise subordinate certificate authority on Windows Server 2016, configure certification services with web enrollment, request and install the certificate from the route CA, and publish CRL and CDP/AIA.
Plan and perform a SHA-1 to SHA-2 hashing migration on Windows Server 2016, covering internal and external certificates, root and subordinate CAs, and CSP to KSP switch.
Learn how to migrate a root CA from sha1 to sha256 by backing up, migrating keys to ksp, updating registry, renewing the certificate, and generating a new crl.
Celebrate completing the course and reflect on your learning journey. Revisit the material if you feel unsure, contact the instructor with questions, and consider leaving a review.
What is this course about?
Do you wonder how SSL works on websites? And what is the significance of digital certificates in secure communication between two entities e.g. a client and a web server? Then you are in the right place.
In this course, we'll talk about PKI which means Public Key Infrastructure. This course provides students with the knowledge and skills to deploy and manage a 2-tier public key infrastructure (PKI) on windows servers to support applications that require certificate based security. Students get hands-on experience implementing the solution to secure websites, applications and devices.
Note: "This course is purely related to Microsoft PKI on windows server a.k.a. Active Directory Certificate Services (ADCS), Please go through the curriculum thoroughly before purchasing the course"
What kind of materials are used?
I’ve designed this course using Microsoft Official Curriculum (MOC). Training will be done through videos where you’ll find lectures and hands-on.
Why take this Course?
There are many reasons to take this course.
One of the Best courses with more than a 4-star rating on this topic.
This course is designed according to Microsoft Official Curriculum and taught by Microsoft Certified Trainer.
Knowing the understanding level of students whether they are a beginner or advanced, this course is designed for all levels making it the best fit for everyone.
You'll find lots of Hands-On in this course which will make you practically sound.
And moreover, security is a hot subject in today's digital age, so why not learn about one of the major and most popular technique to secure your IT Infrastructure.
At last, I am eager to see you succeed, I am offering you my help, assistance wherever required in learning this course. You can drop your queries in the Q&A section of the course and I'll make sure it will be responded promptly.
30/11/2018
Course updated: Included Lectures on Migrating Hashing Algorithm from SHA1 to SHA2