...
- Open Server Manager.
- Click on the name of the Manage menu item and select Add roles and components.
- In the window Wizard for Adding Roles and Components read the information and click on the Next button.
- Set the switch to Install roles or components and click on the Next button.
- Set the switch to Select a server from the server pool.
- In the table Server pool click on the name of the required server.
- Click on the Next button.
- Check the box of the Active Directory Certificate Services.
- In the window that appears, click on Add components. As a result, a checkbox will be displayed next to the name of the selected server role.
- Click on the Next button.
- In the window for the selection of components, click on the Next button.
- Read the information and click on the Next button.
- Select the Certificate Center checkbox and click on the Next button.
- To start the installation process, click Install.
- Wait for the installation process to complete and click on the [Close] button button.
- On the left side of the window Server Manager click on the item name Active Directory Certification Services.
- Click on the exclamation mark.
- Click on the link Configure Active Directory Certificate Services.
- Read the information and click on the Next button.
- Select the Certificate Center checkbox and click on the Next button.
- Set the switch next to the name of the required CC installation option (in this example, the company's CС is selected) and click Next.
- Set the switch next to the name of the CC type (in this example, select the Root CC, since this will be the main certification center in the domain). Click on the Next button.
- In the window for specifying the type of private key, specify the secret key that will be used for the certification center (in this example, select Create a new private key, because a secret key for the certification center has not been created before). Click on the Next button.
- In the next window, to specify the encryption parameters, select an encryption provider in the drop-down list Select an encryption service provider.
- In the drop-down list called Key length select the desired value.
- Click on the name of the required hash algorithm.
- Click on the Next button.
- In the window to specify the name of the CC, enter the values of all fields and click on the Next.
The data entered here is informative. It is recommended to specify them. Abbreviations have the following meaning: "O" — - Organization, "OU" — - Organization Unit, "L" - City (Location), "S" — - State or province, "C" — - Country/region, "E" - E-mail. - Enter the validity period of the certificate to create a CC.
Upon expiration of the CC certificate, it will be necessary to reissue the certificates to all existing users. - In the field Location of the certificate database enter the path to the certificate database and click Next.
- Read the information and click on the Configure button.
- Wait for the installation process to complete and click on the Close button.
...