Overview
A two-tier Microsoft Public Key Infrastructure built in a lab environment, with an offline root certification authority and a domain-joined enterprise issuing CA. The whole deployment is automated with PowerShell.
Design
- An offline root CA, kept offline and used to sign the issuing CA.
- A domain-joined Enterprise issuing CA for day-to-day certificate issuance.
- RSA 4096-bit keys with SHA-256.
Automation
- PowerShell scripts that run through numbered phases for both CAs.
- On the issuing CA, automated creation of the PKI Group Policy, certificate import, and domain enforcement.
- Refined across versions to improve reliability, including reboot handling.
Tools
Windows Server, Active Directory Certificate Services, Group Policy, PowerShell.