Windows Server – PKI Deployment and Management (PKI)

Cybersecurity, ICT Security

The PKI – Electronic Signatures in Practice for Administrators course is designed for system administrators and anyone interested in secure communication over the Internet and LAN networks. During the training, participants will learn to make full use of standard PKI mechanisms available in Windows Server and MS Office applications.

All topics are covered primarily through practical laboratory exercises. Participants will learn to work with certificates on client systems and master the fundamentals of certification authority administration.

THIS TRAINING COURSE WILL HELP YOU:

  • Gain practical skills in PKI and electronic signature administration
  • Understand the principles and importance of PKI
  • Learn to install, configure and manage certification authorities using Windows Server services

WHO SHOULD ATTEND?

  • System and network administrators involved in securing communications
  • Professionals using PKI in Windows environments
  • Anyone interested in secure management of certificates and electronic signatures

COURSE LOCATION AND AVAILABLE DATES



Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English
Podívejte se také na obsahově podobné školení Windows Server – Security Management in Practice (BZP2), ke kterému pravidelně vypisujeme veřejné termíny.

Course content:

Hide details
  • Cryptography, Certificates and PKI Principles
    1. Basic cryptographic principles used in Windows environments
    2. Symmetric and asymmetric encryption
    3. Electronic signatures
    4. Hash functions
    5. Trust principles in Public Key Infrastructure
    6. Digital certificates and their structure
    7. Chain of trust and certificate validation
    8. Certificate types and their uses
    9. Key Usage and Extended Key Usage (EKU)
    10. Subject Alternative Name (SAN)
    11. CryptoAPI and Cryptographic Service Providers (CSP)
    12. Cryptography API: Next Generation (CNG)
    13. Key Storage Providers (KSP)
    14. Private key security
    15. Certificate lifecycle
    16. Current state of post-quantum cryptography in Windows Server 2025
    17. Support, requirements and limitations of post-quantum algorithms, especially ML-DSA, in AD CS
  • Enterprise PKI Design
    1. Certification authority hierarchy design
    2. Root CA and Subordinate CA
    3. Enterprise CA and Standalone CA
    4. Online and offline certification authorities
    5. Separation of root and issuing certification authorities
    6. Design of a secure and manageable PKI infrastructure
    7. Certification authority lifecycle planning
    8. Protection of certification authority private keys
    9. Use of HSM modules
    10. Planning PKI availability, recovery and long-term management
  • Active Directory Certificate Services Deployment and Management
    1. Installing Active Directory Certificate Services
    2. Configuring the certification authority
    3. CA administration and maintenance
    4. Certificate Templates
    5. Designing and modifying certificate templates
    6. Template permissions
    7. Defining the purpose of issued certificates
    8. Secure certificate issuance for users and computers
    9. Manual certificate issuance and management
    10. certreq and certutil tools
    11. Importing and exporting certificates and private keys
    12. Automated certificate issuance
    13. Group Policy and autoenrollment
    14. Autoenrollment for computers and users
    15. Certificate revocation management
    16. Certificate Revocation List (CRL)
    17. Authority Information Access (AIA)
    18. Certificate validity checking
    19. Online Responder and OCSP
    20. Certification authority backup and recovery
    21. Backing up the certificate database and private keys
  • Modern Enrollment and Certificate Issuance Automation
    1. SCEP and Network Device Enrollment Service (NDES)
    2. Automated enrollment scenarios
    3. Issuing certificates to devices and services
    4. Overview of the ACME protocol
    5. Overview of the EST protocol
    6. Options and limitations for their use in Microsoft Windows and AD CS environments
    7. Selecting the appropriate enrollment mechanism for the device or service type
  • Practical PKI Applications
    1. TLS certificates and their deployment
    2. Certificates for Internet Information Services (IIS)
    3. Certificates for Remote Desktop Services and RDP
    4. Using certificates with other server services
    5. TLS hardening
    6. Secure configuration of supported protocols and ciphers
    7. Certificate pinning
    8. Overview of TLS attacks and protective measures
    9. Using certificates to authenticate IPsec communications
    10. Certificate-based user and computer authentication
    11. Encrypting File System (EFS)
    12. Centralized EFS configuration using Group Policy
    13. EFS key management
    14. Data Recovery Agent and recovery scenarios
    15. S/MIME
    16. Electronic signing and encryption of email messages
    17. Certificate management in email scenarios
    18. Using PKI in Exchange and other enterprise services
  • Active Directory Certificate Services Security
    1. AD CS security model
    2. Protecting certification authorities and their private keys
    3. Secure Certificate Templates configuration
    4. Risks of improperly configured template permissions
    5. Risks of uncontrolled enrollment
    6. Certificate-based attacks against Active Directory
    7. Overview of attacks known as ESC1–ESC15
    8. Typical configuration errors enabling privilege escalation
    9. Using certificates to authenticate and take over identities
    10. Auditing Active Directory Certificate Services environments
    11. Monitoring certificate issuance and use
    12. Detecting suspicious enrollment
    13. AD CS hardening
    14. Practical security assessment of deployed PKI
    15. Verifying configuration using laboratory scenarios
Prerequisites:
Knowledge of working with Windows or Linux operating systems. Basic understanding of security in TCP/IP networks.
Schedule:
3 days (9:00-17:00)

Training and learning environment