From 5fecfe4bf233c2f325c26d169513b88adda34b38 Mon Sep 17 00:00:00 2001 From: Nicole Rappe Date: Fri, 11 Jul 2025 18:03:34 -0600 Subject: [PATCH] Update Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md --- .../Roles/Active Directory Certificate Services/Deployment.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md b/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md index fbc7041..da4a450 100644 --- a/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md +++ b/Workflows/Windows/Windows Server/Roles/Active Directory Certificate Services/Deployment.md @@ -45,6 +45,9 @@ This document outlines the Microsoft-recommended best practices for deploying a - Set the key length to `4096` - Set the hash algorithm to SHA256 +!!! info "RSA#Microsoft Software Key Storage Provider" + Microsoft Software Key Storage Provider (KSP) is the latest, most flexible provider designed to work with the Cryptography Next Generation (CNG) APIs. It offers better support for modern algorithms and improved security management (such as support for key attestation, better hardware integration, and improved key protection mechanisms). + !!! warning "Raw Unprocessed Documentation - Do Not Use" 3. 10-year validity. 4. Configure AIA and CDP extensions with HTTP paths.