Tag: Certificate Authority

Convert your Microsoft CA from RSASSA-PSS to sha256RSA

Convert your Microsoft CA from RSASSA-PSS to sha256RSA

During installation of trusted SSL certificates for a VMware vSphere 7.0 lab environment, I ran into the following error when I was trying to replace the certificates: ERROR certificate-manager 'lstool get-site-id' failed: 1 This error was logged on my VCSA, in the /storage/log/vmware/vmcad/certificate-manager.log file. Some searching found VMware KB71120, which...

Windows Server 2019 Two-Tier PKI CA Pt. 2

Windows Server 2019 Two-Tier PKI CA Pt. 2

Now that our root Windows Server 2019 certificate authority is installed and published to Active Directory from Part 1, it is time to bring online our subordinate CA. The subordinate CA will be our online issuing CA, since it will be the CA which issues all certificates, be they for...

Windows Server 2019 Two-Tier PKI CA Pt. 1

Windows Server 2019 Two-Tier PKI CA Pt. 1

Its been quite some time since I wrote up how to setup a Microsoft Windows two-tier certificate authority (CA). While Windows Server 2019 is not new, I did want to write up how to set a two-tier certificate authority (CA). I'm building out a new home lab, and thought this...

Windows Server 2012 R2 Two-Tier PKI CA Pt. 3

Now that we have our Windows Server 2012 R2 certificate authority configured in Part 1, and our subordinate setup in Part 2, now we should setup autoenrollment and secure the subordinate's web certificate services with SSL. Autoenrollment is where domain joined Windows computers are automatically issued a computer certificate. Services such...

Windows Server 2012 R2 Two-Tier PKI CA Pt. 2

Now that our root Windows Server 2012 R2 certificate authority is installed and published to Active Directory from Part 1, it is time to bring online our subordinate CA. The subordinate CA will be our online issuing CA, since it will be the CA which issues all certificates, be they for users,...

Windows Server 2012 R2 Two-Tier PKI CA Pt. 1

Windows Server 2012 R2 Two-Tier PKI CA Pt. 1

While I have written a number of articles focused on SSL certificates and templates, I have not done a mini-series on how to actually install a Windows Certificate Authority. For this series I'm using Windows Server 2012 R2, but the steps are pretty much identical for Windows Server 2012. Microsoft...