็†ฑ้–€ๅˆ†้กž
 ่ผ‰ๅ…ฅไธญ…
็›ฎ้Œ„

๐ŸชŸ Windows CA ๆ†‘่ญ‰ๆœๅ‹™(AD CS)ๆžถ่จญๅ…จๆ”ป็•ฅ:ไผๆฅญๆ†‘่ญ‰、Auto-Enrollment、HTTPS/SMB/EAP ๅฏฆๅ‹™ๆ‡‰็”จ

    ๐ŸชŸ Windows CA ๆ†‘่ญ‰ๆœๅ‹™(AD CS)ๆžถ่จญๅ…จๆ”ป็•ฅ:ไผๆฅญๆ†‘่ญ‰、Auto-Enrollment、HTTPS/SMB/EAP ๅฏฆๅ‹™ๆ‡‰็”จ

    ๅœจไผๆฅญ็ถฒ่ทฏไธญ,ๆ†‘่ญ‰(Certificate) ๆ˜ฏๆ”ฏๆ’ๅฎ‰ๅ…จๆžถๆง‹็š„ๆ ธๅฟƒ:HTTPS、SMB ็ฐฝ็ฝฒ、Wi-Fi EAP-TLS、VPN、RDP、Intune、SQL Server… ้€™ไบ›้ƒฝ้œ€่ฆๅฏ้ ็š„ PKI(Public Key Infrastructure)ไพ†็ฎก็†ๆ†‘่ญ‰,่€Œๅœจ Windows ไผๆฅญ AD ็’ฐๅขƒไธญๆœ€ๅฎŒๆ•ด็š„ๆ–นๆกˆๅฐฑๆ˜ฏ AD CS(Active Directory Certificate Services)

    ๆœฌๆ–‡ๅฐ‡ๆ‰‹ๆŠŠๆ‰‹ๅธถไฝ ๅฎŒๆˆ Windows ไผๆฅญๅ…ง้ƒจ CA ๆžถ่จญ、ๆ†‘่ญ‰็ฏ„ๆœฌ่จญ่จˆ、Auto-Enrollment、ๆœๅ‹™ๆ†‘่ญ‰ไฝˆ็ฝฒ、EAP-TLS Wi-Fi ้ฉ—่ญ‰、ๆ†‘่ญ‰็ฎก็† ็ญ‰ๅ…จ้ƒจๆต็จ‹, ๆ‰“้€ ๅฏๆญฃๅผไธŠ็ทš็š„ไผๆฅญ็ดš PKI ๆœๅ‹™。


    ๐Ÿ“‘ ็›ฎ้Œ„


    ไธ€、AD CS ่ˆ‡ไผๆฅญ PKI ๆžถๆง‹ๆฆ‚ๅฟต

    AD CS ๆ˜ฏ Windows Server ็š„ PKI ๆœๅ‹™,่ฒ ่ฒฌ:

    • ็ฐฝ็™ผๆ†‘่ญ‰(Issue Certificates)
    • ๆ’ค้Šทๆ†‘่ญ‰、็™ผๅธƒ CRL
    • ๆ†‘่ญ‰็ฏ„ๆœฌ、็”ณ่ซ‹่ฆๅ‰‡、ไฝฟ็”จ่€…ๆŽˆๆฌŠ
    • ๆ•ดๅˆ Active Directory,่‡ชๅ‹•ๆดพ็™ผๆ†‘่ญ‰(Auto-Enrollment)

    ไผๆฅญไธญๅธธ็”จๆ†‘่ญ‰็”จ้€”ๅŒ…ๆ‹ฌ:

    • Windows Server / IIS HTTPS
    • SMB ็ฐฝ็ฝฒ / LDAP over SSL
    • Wi-Fi 802.1X(EAP-TLS)
    • VPN(SSTP、OpenVPN、FortiGate、IPsec)
    • SQL Server / Exchange
    ๅฎŒๆ•ด PKI ๆžถๆง‹็คบๆ„:
    
           Root CA(้›ข็ทš)
               │
               ▼
          Issuing CA(็ทšไธŠ)
               │
               ├── ไฝฟ็”จ่€…ๆ†‘่ญ‰(User / SmartCard)
               ├── ้›ป่…ฆๆ†‘่ญ‰(Computer / Workstation)
               ├── ไผบๆœๅ™จๆ†‘่ญ‰(Web / RDP / LDAP)
               └── ็ถฒ่ทฏๆ†‘่ญ‰(EAP-TLS / VPN)
    

    ไบŒ、PKI ่ง’่‰ฒ:Root CA、Sub CA、Issuing CA

    ๅปบ่ญฐไผๆฅญ็’ฐๅขƒๆŽก็”จๅ…ฉๅฑคๆžถๆง‹:

    1. Root CA(้›ข็ทš)

    • ๅช็”จไพ†็ฐฝ็™ผ Sub CA(Issuing CA)ๆ†‘่ญ‰
    • ๅนณๆ™‚ไธ้–‹ๆฉŸ、ไธไธŠ็ถฒ、ไธๅŠ ๅ…ฅ AD
    • ้‡‘้‘ฐๅฎ‰ๅ…จๆ€งๆฅต้ซ˜

    2. Issuing CA(็ทšไธŠ)

    • ็›ดๆŽฅ็ฐฝ็™ผๆ‰€ๆœ‰ไฝฟ็”จ่€…่ˆ‡ไผบๆœๅ™จๆ†‘่ญ‰
    • ๆ•ดๅˆ AD、GPO,่‡ชๅ‹•ๆดพ็™ผๆ†‘่ญ‰
    • ๆ—ฅๅธธ็‡Ÿ้‹็š„ CA

    ๅฆ‚ๆžœๅ…ฌๅธ่ฆๆจกๅฐ(็ด„ 50 ไบบๅ…ง),ๅฏๅ…่จฑไฝฟ็”จๅ–ฎๅฑค Enterprise Root CA(ๆœฌๆ–‡็คบ็ฏ„ๆญคๆžถๆง‹)。


    ไธ‰、ๅฎ‰่ฃ AD CS:Enterprise Root CA

    1. ๅฎ‰่ฃ AD CS ่ง’่‰ฒ

    # Windows Server GUI ๆ“ไฝœ
    Server Manager → Add Roles and Features → Active Directory Certificate Services
    
    ๅ‹พ้ธ:
    ✓ Certification Authority
    ✓ Certification Authority Web Enrollment(ๅฏ้ธ)
    

    2. ่จญๅฎš AD CS

    ่ง’่‰ฒๅฎ‰่ฃๅฎŒๆˆๅพŒ,ๅŸท่กŒ「Configure AD CS」。

    • CA ้กžๅž‹:Enterprise CA
    • ๅฑค็ดš:Root CA
    • ้‡‘้‘ฐ้•ทๅบฆ:ๅปบ่ญฐ 4096 bit
    • Hash ๆผ”็ฎ—ๆณ•:SHA256
    • CA ๆœ‰ๆ•ˆๆœŸ้™:10–20 ๅนด(ไพไผๆฅญๆ”ฟ็ญ–)

    3. ๆชขๆŸฅ CA ๆ˜ฏๅฆ้‹ไฝœๆญฃๅธธ

    certsrv.msc  → Certification Authority
    
    ๆŸฅ็œ‹:
    ✓ CA ๅ•Ÿๅ‹•ๆˆๅŠŸ
    ✓ ็„ก Error
    ✓ CRL ๅทฒ็™ผๅธƒ

    ๅ››、ๆ†‘่ญ‰็ฏ„ๆœฌ(Certificate Template)่จญ่จˆ

    ๅœจไผๆฅญ้‹ไฝœไธญ,ไธๆœƒๆ‰‹ๅ‹•็‚บๆฏๅฐ้›ป่…ฆ็”ณ่ซ‹ๆ†‘่ญ‰,่€Œๆ˜ฏ้€้Žๆ†‘่ญ‰็ฏ„ๆœฌ(Certificate Template)็ตฑไธ€็ฎก็†้กžๅž‹่ˆ‡ๅฑฌๆ€ง。

    ๅธธ่ฆ‹็ฏ„ๆœฌ:

    • Computer(้›ป่…ฆๆ†‘่ญ‰)
    • User(ไฝฟ็”จ่€…ๆ†‘่ญ‰)
    • Web Server(HTTPS)
    • Smart Card Login / EAP-TLS(Wi-Fi)

    1. ๅปบ็ซ‹็ฏ„ๆœฌ(ไปฅ Computer ็ฏ„ๆœฌ็‚บไพ‹)

    certtmpl.msc → ๅณ้ต่ค‡่ฃฝ "Computer" → ๆ–ฐ็ฏ„ๆœฌๅ‘ฝๅ็‚บ "Corp-Computer-Cert"

    2. ่จญๅฎšๅฎ‰ๅ…จๆ€ง(Security)

    • ๅ…่จฑ Domain Computers:Enroll + Autoenroll

    3. ็™ผไฝˆ็ฏ„ๆœฌ

    certsrv.msc → Certificate Templates → New → Certificate Template to Issue
    
    ้ธๅ–:
    ✓ Corp-Computer-Cert

    ไบ”、Auto-Enrollment ่‡ชๅ‹•ๆดพ็™ผๆ†‘่ญ‰(ไฝฟ็”จ GPO)

    1. ๅปบ็ซ‹ GPO

    gpmc.msc → Create GPO → "PKI Auto Enrollment"

    2. ๅ•Ÿ็”จ่‡ชๅ‹•ๆ†‘่ญ‰ๆดพ็™ผ

    Computer Configuration →
      Policies →
        Windows Settings →
          Security Settings →
            Public Key Policies →
              Certificate Services Client – Auto-Enrollment →
                ✓ Enabled
                ✓ Renew expired certificates
                ✓ Update certificates
                ✓ Enroll certificates automatically
    

    3. ๅฅ—็”จๅˆฐ OU

    ๅฐ‡ GPO ๅฅ—็”จ่‡ณ:
    OU = Workstations
    OU = Servers

    4. ็ซ‹ๅณ้ฉ—่ญ‰

    gpupdate /force
    
    certmgr.msc → ๆ˜ฏๅฆๅ‡บ็พ "Corp-Computer-Cert"

    ๅ…ญ、ๆœๅ‹™ๆ‡‰็”จ:HTTPS、RDP、SMB、EAP-TLS

    1. IIS / HTTPS ๆ†‘่ญ‰

    ็ถฒ็ซ™ๅฎ‰ๅ…จๅŠ ๅฏ†、ๅๅ‘ไปฃ็†、API Server ้ƒฝ้œ€่ฆ Web Server ๆ†‘่ญ‰。

    IIS Manager →
    Server Certificates →
    Create Domain Certificate →
    ้ธๆ“‡ CA →
    ๅฎŒๆˆๅพŒ็ถๅฎš HTTPS ๅŸ ๅฃ(443)
    

    2. RDP ๆ†‘่ญ‰(ๅ–ไปฃ่‡ช็ฐฝ RDP ๆ†‘่ญ‰)

    gpedit.msc →
    Computer Configuration →
    Administrative Templates →
    Windows Components →
    Remote Desktop Services →
    Remote Desktop Session Host →
    Security →
    ้ธๆ“‡ๆ†‘่ญ‰:Corp-Computer-Cert
    

    3. SMB ็ฐฝ็ฝฒ(SMB Signing / LDAP over SSL)

    ไฝฟ File Server / AD DS ่ง’่‰ฒๆไพ›ๆ›ดๅฎ‰ๅ…จ็š„ๅŠ ๅฏ†。

    4. Wi-Fi EAP-TLS(802.1X + NPS)

    ๆœ€ๅฎ‰ๅ…จ็š„ไผๆฅญ Wi-Fi ่ช่ญ‰ๆ–นๅผ:

    • ็„กๅฏ†็ขผ、็„กๅฏ้‡ๆ”พๆ”ปๆ“Š
    • ็ตๅˆ Auto-Enrollment ๅ…จ่‡ชๅ‹•็™ผๆ†‘่ญ‰
    ๆญฅ้ฉŸๆฆ‚่ฆ:
    NPS → RADIUS Server
    ๆ†‘่ญ‰:Server ่ˆ‡ Client ๅ‡ไฝฟ็”จ AD CS ็š„็ฏ„ๆœฌ
    AP → ่จญๅฎš 802.1X(WPA2-Enterprise)
    Client → ๅฎ‰่ฃ/่‡ชๅ‹•ๅ–ๅพ—ๅ€‹ไบบๆ†‘่ญ‰(EAP-TLS)
    

    ไธƒ、CRL / OCSP:ๆ†‘่ญ‰ๆ’ค้Šท่ˆ‡็ทšไธŠๆŸฅ่ฉข

    ๅฎ‰ๅ…จๆ”ฟ็ญ–้œ€่ฆๅฏ「ๆ’ค้Šท」ๆ†‘่ญ‰,ไพ‹ๅฆ‚:ๅ“กๅทฅ้›ข่ท、่ฃ็ฝฎ้บๅคฑ。

    1. ๆ’ค้Šทๆ†‘่ญ‰

    certsrv.msc → Issued Certificates → ๅณ้ต Revoke

    2. ็ขบไฟ CRL ๅฏ่ขซ Client ๅญ˜ๅ–

    ไผๆฅญๅธธไฝฟ็”จ:

    • CRL Distribution Point(CDP):HTTP
    • AIA:HTTP
    ่‹ฅ่ฆๅ•Ÿ็”จ OCSP,ๅฏๅฆๅฎ‰่ฃ Online Responder:
    Server Manager → Add Roles → Active Directory Certificate Services →
    ✓ Online Responder

    ๅ…ซ、PKI ็ถญ่ญท:CA ๅ‚™ไปฝ、้‡‘้‘ฐไฟ่ญท、ๆ†‘่ญ‰ๅˆฐๆœŸ

    1. ๅ‚™ไปฝ CA ้‡‘้‘ฐ่ˆ‡่ณ‡ๆ–™ๅบซ

    certutil -backupkey C:\CA-Backup
    certutil -backupdb C:\CA-Backup

    2. ๆ†‘่ญ‰ๆœ‰ๆ•ˆๆœŸ้™่ˆ‡ๆ›ดๆ–ฐ

    ไผๆฅญๆ‡‰ๅปบ็ซ‹「ๆ†‘่ญ‰ๅˆฐๆœŸ็›ฃๆŽง」,ไพ‹ๅฆ‚ SQL、IIS、NPS ็ญ‰ๆœๅ‹™็š„ๆ†‘่ญ‰。

    3. AD CS ็งปๆฉŸ / ็ฝ้›ฃๅพฉๅŽŸ

    ๅƒ…้œ€:CA ้‡‘้‘ฐ、CA Database、CA ่จญๅฎš。


    ไน、้Œฏ่ชคๆŽ’ๆŸฅ่ˆ‡่จบๆ–ท

    1. ๆ†‘่ญ‰ๆฒ’ๆœ‰่‡ชๅ‹•ๆดพ็™ผ

    • GPO ๆฒ’ๅฅ—็”จ
    • ็ฏ„ๆœฌๆœชๅ…่จฑ Autoenroll
    • CA ๆœช Publish ็ฏ„ๆœฌ

    2. HTTPS ็„กๆณ•็ถๅฎšๆ†‘่ญ‰

    • ็ผบๅฐ‘ Private Key
    • ๆ†‘่ญ‰็„ก Server Authentication EKU

    3. Wi-Fi EAP-TLS ็„กๆณ•็™ปๅ…ฅ

    • Client ๆœชๅ–ๅพ—ๅ€‹ไบบๆ†‘่ญ‰
    • NPS ๆœชๅฎ‰่ฃ Server ๆ†‘่ญ‰

    — WWFandy・Windows PKI ็ญ†่จ˜

    ๐Ÿ”— ๅˆ†ไบซ้€™็ฏ‡ LINE Facebook X

    ๆฒ’ๆœ‰็•™่จ€:

    ๅผต่ฒผ็•™่จ€

    ๅญ—็ดš