Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
PKI - Certificate Infrastructure
Rating: 4.3 out of 5(6 ratings)
31 students

PKI - Certificate Infrastructure

Implementing PKI infrastructure in a organization
Created byMoiz Kareem
Last updated 1/2025
English
English [Auto],

What you'll learn

  • Public key infrastructure
  • How traffic is encrypted using certificates
  • Authentication via certificates
  • Types of certificate extensions

Course content

1 section • 11 lectures • 2h 9m total length
  • Introduction20:29

    Explore how public key infrastructure uses certificates from certificate authorities to secure web traffic, with root and subordinate CAs, certification paths, and encryption locks.

  • Certificate Authority7:17

    Explore certificate authority services, including web enrollment, web auto enrollment, policy groups, and online responders, and how they issue certificates and verify revocation via CRL, OCSP, and CDP.

  • Topology2:57

    Configure a lab PKI topology with a domain controller, root and subordinate CAs, web enrollment, policy server, and OCSP services on Windows Server 2016 and Windows 11.

  • Installing & Configuring AD & DNS Roles6:27

    Install and configure Active Directory and DNS services, promote the server to a domain controller for a new forest and domain, then log in as domain administrator.

  • Configuring RootCA11:15

    Install and configure the root certificate authority by domain joining, selecting a standalone root certificate authority, and configuring the subordinate certificate authority with CRL and CDP links for issuance.

  • Configuring Sub-ordinate CA16:29

    Configure and deploy a subordinate CA within an existing PKI by generating a certificate signing request, issuing the subordinate certificate from the root CA, and enabling web enrollment and templates.

  • Securing domain website converting into https5:23

    Learn how to secure a domain by creating a certificate signing request, obtaining a CA-signed certificate, and binding HTTPS on port 443 using IIS manager.

  • Securing domain webserver converting into https12:52

    Generate a CSR in IIS, obtain a certificate from the subordinate CA, install the certificate chain including the root CA, then bind https on port 443 to encrypt traffic.

  • Configuring domain polices to issues certificates to machines & users22:23

    Configure domain policies to auto enroll user and computer certificates by crafting templates, enabling auto enrollment in group policy, and publishing certificates in Active Directory to support AAA server authentication.

  • Certificate Extension Types9:35

    Explore certificate extension types such as base64, p12, and p7b, and distinguish extensions that store private keys, public keys, and certificate chains from certificate-only formats.

  • Online Responder to verify certificate13:59

    Learn how online certificate responders use OCSP to verify certificates without downloading large CRL lists, configure OCSP response signing, publish the OCSP URL, and validate certificates.

Requirements

  • Basic understanding of windows server 2016
  • Basic understanding of windows 11

Description

In this course, we will explore the fundamentals of Public Key Infrastructure (PKI) and its role in securing digital applications, transactions, identities, and supply chains. By the end of this course, you will have a comprehensive understanding of how PKI works, its components, and its applications.

Public Key Infrastructure (PKI) is a system that uses digital certificates to authenticate users, devices, and services. PKI uses asymmetric encryption to create a secure connection for data encryption and signing.

How PKI works

  1. An organization requests a digital certificate from a Certificate Authority (CA).

  2. The Registration Authority (RA) verifies the identity of the organization or user.

  3. The CA issues the digital certificate, which is signed with the CA's private key.

  4. The CA publishes the public key, which can be used to encrypt or verify a digital signature.

  5. The public key is used to encrypt data, which is then decrypted with the private key.

Components of PKI

  • Certificate Authority (CA)

    A trusted third-party that issues, stores, and signs digital certificates. CAs also maintain a Certificate Revocation List (CRL).

  • Registration Authority (RA)

    Verifies the identity of the user or device requesting a digital certificate.

  • Digital Certificate

    An electronic credential that authenticates the identity of a user, device, or service.

  • Certificate Lifecycle Management (CLM)

    Manages the lifecycle of digital certificates, including issuing, renewing, and revoking them.

PKI is used to secure digital applications, transactions, identities, and supply chains.


Who this course is for:

  • Beginners, students, learners