Overview

A two-tier Microsoft Public Key Infrastructure built in a lab environment, with an offline root certification authority and a domain-joined enterprise issuing CA. The whole deployment is automated with PowerShell.

Design

  • An offline root CA, kept offline and used to sign the issuing CA.
  • A domain-joined Enterprise issuing CA for day-to-day certificate issuance.
  • RSA 4096-bit keys with SHA-256.

Automation

  • PowerShell scripts that run through numbered phases for both CAs.
  • On the issuing CA, automated creation of the PKI Group Policy, certificate import, and domain enforcement.
  • Refined across versions to improve reliability, including reboot handling.

Tools

Windows Server, Active Directory Certificate Services, Group Policy, PowerShell.