CA Roles
Active Directory Certificate Services (AD CS) relies on Certificate Authority (CA) roles to manage trust and certificate issuance. Configuring these roles correctly is critical for maintaining security, compliance, and operational reliability. This section details the setup and security considerations for the primary CA roles: Stand-alone, Enterprise, Root, and Subordinate.
Stand-alone CA Configuration¶
A Stand-alone CA operates independently of Active Directory Domain Services (AD DS) and is typically used in smaller environments or for non-AD-integrated services.
Configuration Steps¶
-
Install the CA Role:
Follow the wizard to select "Stand-alone CA" and specify the CA name and validity period.
Use Server Manager or PowerShell:
-
Configure Certificate Templates:
Use the Certification Authority snap-in (certsrv.msc) to define templates for issued certificates (e.g., code signing, client authentication). -
Set Access Control:
Assign permissions via the CA’s properties in the Certification Authority snap-in to restrict who can request or revoke certificates.
Security Implications¶
- Isolation: Ensure the Stand-alone CA is isolated from AD DS and other network segments.
- Key Protection: Store private keys in a Hardware Security Module (HSM) or secure local storage.
- Audit Logs: Enable auditing for certificate issuance and revocation to detect unauthorized activity.
Enterprise CA Configuration¶
An Enterprise CA integrates with AD DS and is used in domain environments. It can be a Root or Subordinate CA.
Configuration Steps¶
-
Promote the Server:
Usedcpromoor Server Manager to promote the server to a domain controller (if required). -
Install the CA Role:
During installation, select "Enterprise CA" and choose whether to create a Root CA or Subordinate CA. -
Configure AD Integration:
- Link the CA to the domain via the Certification Authority snap-in.
- Use Group Policy to deploy certificate templates and enforce enrollment policies.
Security Implications¶
- AD Permissions: Restrict CA administration permissions to trusted administrators via AD groups.
- Secure Communication: Use Kerberos for secure communication between the CA and AD DS.
- Certificate Templates: Enforce strict templates (e.g., enforce encryption key usage) to prevent misuse.
Root CA Configuration¶
A Root CA is the top-level trust anchor in a PKI hierarchy. It must be configured with the highest security standards.
Configuration Steps¶
-
Create the Root CA:
Use the Certification Authority snap-in to create a new Root CA, specifying a validity period (e.g., 10 years). -
Export the Root Certificate:
Distribute the root certificate to trusted systems via Group Policy or manual installation. -
Enable Key Archival:
Configure a key recovery agent and archive private keys for disaster recovery.
Security Implications¶
- Physical Security: Protect the Root CA’s private key with hardware security modules (HSMs).
- Access Control: Limit access to the CA’s private key to a small, trusted group.
- Regular Audits: Monitor certificate issuance and revocation logs for anomalies.
Subordinate CA Configuration¶
A Subordinate CA issues certificates signed by a Root or another Subordinate CA. It is used to decentralize certificate management.
Configuration Steps¶
-
Create the Subordinate CA:
Use the Certification Authority snap-in to create a new Subordinate CA, specifying the parent CA’s certificate. -
Configure Trust Relationships:
Ensure the Subordinate CA’s certificate is trusted by downstream systems. -
Set Policy Constraints:
Define policies to restrict certificate issuance (e.g., only allow specific templates).
Security Implications¶
- Chain of Trust: Ensure the Subordinate CA’s certificate is properly signed by a trusted Root CA.
- Network Segmentation: Isolate Subordinate CAs from external networks to prevent unauthorized access.
- Monitoring: Track certificate requests and revocations to detect potential misuse.
Key takeaways¶
- Role Distinction: Stand-alone CAs are isolated, while Enterprise CAs integrate with AD DS. Root CAs form the trust anchor, and Subordinate CAs decentralize management.
- Security Best Practices: Use HSMs for private key storage, enforce strict access controls, and enable auditing for all CA operations.
- Policy Enforcement: Leverage certificate templates and Group Policy to standardize certificate issuance and reduce risks of misconfiguration.