Administration

Table Of Contents
3 On the Select Server Roles page, select Active Directory Certificate Services.
4 In the Add Roles and Features wizard, click Add Features, and leave the Include management
tools check box selected.
5 On the Select Features page, accept the defaults.
6 On the Select Role Services page, select Certification Authority.
7 Follow the prompts and finish the installation.
8 When installation is complete, on the Installation Progress page, click the Configure Active
Directory Certificate Services on destination server link to open the AD CS Configuration
wizard.
9 On the Credentials page, click Next and complete the AD CS Configuration wizard pages as
described in the following table.
Option Action
Role Services Select Certification Authority, and click Next (rather than Configure).
Setup Type Select Enterprise CA.
CA Type Select Root CA or Subordinate CA. Some enterprises
prefer two-tier PKI deployment. For more information,
see http://social.technet.microsoft.com/wiki/contents/articles/15037.ad-cs-
step-by-step-guide-two-tier-pki-hierarchy-deployment.aspx.
Private Key Select Create a new private key.
Cryptography for CA For hash algorithm, you can select SHA1, SHA256, SHA384, or SHA512. For
key length, you can select 1024, 2048, 3072, or 4096.
VMware recommends a minimum of SHA256 and a 2048 key.
CA Name Accept the default or change the name.
Validity Period Accept the default of 5 years.
Certificate Database Accept the defaults.
10 On the Confirmation page, click Configure, and when the wizard reports a successful
configuration, close the wizard.
11 Open a command prompt and enter the following command to configure the CA for non-
persistent certificate processing:
certutil -setreg DBFlags +DBFLAGS_ENABLEVOLATILEREQUESTS
12 Enter the following command to ignore offline CRL (certificate revocation list) errors on the CA:
certutil -setreg ca\CRLFlags +CRLF_REVCHECK_IGNORE_OFFLINE
This flag is required because the root certificate that True SSO uses will usually be offline, and
thus revocation checking will fail, which is expected.
Horizon 7 Administration
VMware, Inc. 99