diff --git a/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md b/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md index fbc7041..da4a450 100644 --- a/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md +++ b/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md @@ -45,6 +45,9 @@ This document outlines the Microsoft-recommended best practices for deploying a - Set the key length to `4096` - Set the hash algorithm to SHA256 +!!! info "RSA#Microsoft Software Key Storage Provider" + Microsoft Software Key Storage Provider (KSP) is the latest, most flexible provider designed to work with the Cryptography Next Generation (CNG) APIs. It offers better support for modern algorithms and improved security management (such as support for key attestation, better hardware integration, and improved key protection mechanisms). + !!! warning "Raw Unprocessed Documentation - Do Not Use" 3. 10-year validity. 4. Configure AIA and CDP extensions with HTTP paths.