Restructured Documentation
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
---
|
||||
tags:
|
||||
- Windows Server
|
||||
- Windows
|
||||
- SSL
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Sometimes you may find that you need to convert a `.crt` or `.pem` certificate file into a `.pfx` file that Microsoft IIS Server Manager can import for something like Exchange Server or another custom IIS-based server.
|
||||
|
||||
## Download the Certificate Files
|
||||
This step will vary based on how you are obtaining the certificates. The primary thing to focus on is making sure you have the certificate file and the private key.
|
||||
|
||||
```text title="Certificate Folder Structure"
|
||||
certificate.crt
|
||||
certificate.pem
|
||||
gd-g2_iis_intermediates.p7b
|
||||
private.key
|
||||
```
|
||||
|
||||
## Convert using OpenSSL
|
||||
You will need a linux machine such as Ubuntu 22.04LTS, or to download the Windows equivelant of OpenSSL in order to run the necessary commands to convert and package the files into a `.pfx` file that IIS Server Manager can use.
|
||||
!!! note
|
||||
You need to make sure that all of the certificate files as well as private key are in the same folder (to keep things simple) during the conversion process. **It will prompt you to enter a password for the PFX file, choose anything you want.**
|
||||
|
||||
```sh title="OpenSSL Conversion Command"
|
||||
openssl pkcs12 -export -out IIS-Certificate.pfx -inkey private.key -in gd-g2_iis_intermediates.p7b -in certificate.crt
|
||||
```
|
||||
|
||||
!!! tip
|
||||
You can rename the files anything you want for organizational purposes. Afterall, they are just plaintext files. For example, you could rename `gd-g2_iis_intermediates.p7b` to `intermediate.bundle` and it would still work without issue in the command. During the import phase in IIS Server Manager, you can check a box to enable Exporting the certificate, effectively reverse-engineering it back into a certificate and private key.
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
+51
@@ -0,0 +1,51 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- LDAPS
|
||||
- Certificates
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Export the CA chain or domain-controller certificate required by an application that connects to Active Directory over LDAPS. Use the certificate objects from the documented CA and domain-controller environment.
|
||||
|
||||
## Export the LDAPS Certificate for Third-Party Applications
|
||||
Some applications do not automatically trust your internal PKI and require you to manually install the certificate used by your domain controllers for LDAPS. In most cases, you should export the issuing CA certificates rather than the individual domain controller certificate. Only export the domain controller certificate if the third-party application explicitly requires it.
|
||||
|
||||
### Export the Root and Subordinate CA Certificates
|
||||
The Root CA and Subordinate CA certificates establish trust for every domain controller certificate issued by your PKI.
|
||||
|
||||
From any domain-joined system:
|
||||
|
||||
- Launch `certlm.msc`
|
||||
- Navigate to "**Trusted Root Certification Authorities > Certificates**"
|
||||
- Locate your Root CA certificate
|
||||
- Right-click the certificate and select "**All Tasks > Export...**"
|
||||
- Select "**No, do not export the private key**"
|
||||
- Export the certificate as either:
|
||||
- `DER encoded binary X.509 (.CER)`, or
|
||||
- `Base-64 encoded X.509 (.CER)`
|
||||
- Navigate to "**Intermediate Certification Authorities > Certificates**"
|
||||
- Locate your Subordinate CA certificate
|
||||
- Repeat the export process
|
||||
|
||||
Import both certificates into the trusted certificate store required by the third-party application.
|
||||
|
||||
### Export a Domain Controller Certificate
|
||||
If the application requires the LDAPS server certificate itself:
|
||||
|
||||
- On the target domain controller, launch `certlm.msc`
|
||||
- Navigate to "**Personal > Certificates**"
|
||||
- Locate the certificate issued to the domain controller's FQDN that includes **Server Authentication** as an intended purpose
|
||||
- If the certificate's intended purpose looks like `Client Authentication, Server Authentication, Smart Card Logon, KDC Authentication` this cert may be more versatile for you.
|
||||
- Right-click the certificate and select "**All Tasks > Export...**"
|
||||
- Select "**No, do not export the private key**"
|
||||
- Export the certificate as either:
|
||||
- `DER encoded binary X.509 (.CER)`, or
|
||||
- `Base-64 encoded X.509 (.CER)`
|
||||
|
||||
!!! warning "Do Not Export the Private Key"
|
||||
Third-party LDAPS clients require only the public certificate. Do **not** export the certificate as a `.pfx` file or include the private key unless the vendor explicitly documents that requirement.
|
||||
|
||||
## Related Documentation
|
||||
- [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Identify the CA chain used by the LDAPS clients.
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
+77
@@ -0,0 +1,77 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- Certificate Services
|
||||
- PKI
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Publish the root and subordinate CA revocation lists for the documented two-tier Active Directory certificate environment. The Root CA and HTTP distribution point must already be configured as described in the certificate deployment.
|
||||
|
||||
## CRL Publishing and Maintenance
|
||||
CRLs must be generated and published on a recurring basis. If a CRL expires, certificate validation may fail even if the CA services themselves are running.
|
||||
|
||||
### Root CA CRL Publishing
|
||||
Because the Root CA is offline, periodically bring it online only long enough to generate a new CRL and copy it to the HTTP distribution point.
|
||||
|
||||
On `LAB-CA-01`:
|
||||
|
||||
```powershell
|
||||
certutil -crl
|
||||
```
|
||||
|
||||
Copy the generated CRL from:
|
||||
|
||||
```text
|
||||
C:\Windows\System32\CertSrv\CertEnroll\
|
||||
```
|
||||
|
||||
to the IIS publication directory on `LAB-CA-02`:
|
||||
|
||||
```text
|
||||
C:\inetpub\wwwroot\pki\
|
||||
```
|
||||
|
||||
Validate:
|
||||
|
||||
```powershell
|
||||
Invoke-WebRequest http://pki.bunny-lab.io/pki/BunnyLab-RootCA.crl
|
||||
```
|
||||
|
||||
### Subordinate CA CRL Publishing
|
||||
On `LAB-CA-02`:
|
||||
|
||||
```powershell
|
||||
certutil -crl
|
||||
```
|
||||
|
||||
Copy or confirm the Subordinate CA CRL exists in:
|
||||
|
||||
```text
|
||||
C:\inetpub\wwwroot\pki\
|
||||
```
|
||||
|
||||
Validate the URL from a domain-joined system.
|
||||
|
||||
### Operational Monitoring
|
||||
Monitor CRL expiration and publication. Certificate validation failures can occur if CRLs expire, even if certificates themselves have not expired.
|
||||
|
||||
Recommended operational tasks:
|
||||
|
||||
- Track Root CA CRL expiration.
|
||||
- Track Subordinate CA CRL expiration.
|
||||
- Verify HTTP CRL URLs after each publication.
|
||||
- Keep the Root CA offline except during controlled maintenance windows.
|
||||
- Document the expected CRL filenames generated in `C:\Windows\System32\CertSrv\CertEnroll\`.
|
||||
|
||||
!!! abstract "Raw Unprocessed/Unimplemented Steps"
|
||||
Publish CRLs regularly, configure overlap periods, and monitor expiration. Enable Delta CRLs on the Subordinate CA, but not on the Root.
|
||||
Security Recommendations
|
||||
|
||||
- Harden CA servers; limit access to PKI admins.
|
||||
- Use BitLocker or HSM for key protection.
|
||||
- Monitor issuance and renewals with audit logs and scripts.
|
||||
|
||||
## Related Documentation
|
||||
- [Certificate Services Deployment](<../../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Confirm the CA names, publication paths, and HTTP distribution point.
|
||||
- [Related Identity and Certificates Documentation](<../../../reference/Identity and Certificates/index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
Reference in New Issue
Block a user