๐ช Windows CA ๆ่ญๆๅ(AD CS)ๆถ่จญๅ จๆป็ฅ:ไผๆฅญๆ่ญ、Auto-Enrollment、HTTPS/SMB/EAP ๅฏฆๅๆ็จ
ๅจไผๆฅญ็ถฒ่ทฏไธญ,ๆ่ญ(Certificate) ๆฏๆฏๆๅฎๅ จๆถๆง็ๆ ธๅฟ:HTTPS、SMB ็ฐฝ็ฝฒ、Wi-Fi EAP-TLS、VPN、RDP、Intune、SQL Server… ้ไบ้ฝ้่ฆๅฏ้ ็ PKI(Public Key Infrastructure)ไพ็ฎก็ๆ่ญ,่ๅจ Windows ไผๆฅญ AD ็ฐๅขไธญๆๅฎๆด็ๆนๆกๅฐฑๆฏ AD CS(Active Directory Certificate Services)。
ๆฌๆๅฐๆๆๆๅธถไฝ ๅฎๆ Windows ไผๆฅญๅ ง้จ CA ๆถ่จญ、ๆ่ญ็ฏๆฌ่จญ่จ、Auto-Enrollment、ๆๅๆ่ญไฝ็ฝฒ、EAP-TLS Wi-Fi ้ฉ่ญ、ๆ่ญ็ฎก็ ็ญๅ จ้จๆต็จ, ๆ้ ๅฏๆญฃๅผไธ็ท็ไผๆฅญ็ด PKI ๆๅ。
๐ ็ฎ้
- ไธ、AD CS ่ไผๆฅญ PKI ๆถๆงๆฆๅฟต
- ไบ、PKI ่ง่ฒ:Root CA、Sub CA、Issuing CA
- ไธ、ๅฎ่ฃ AD CS:Enterprise Root CA
- ๅ、ๆ่ญ็ฏๆฌ(Certificate Template)่จญ่จ
- ไบ、Auto-Enrollment ่ชๅๆดพ็ผๆ่ญ(ไฝฟ็จ GPO)
- ๅ ญ、ๆๅๆ็จ:HTTPS、RDP、SMB ็ฐฝ็ฝฒ、Wi-Fi EAP-TLS
- ไธ、CRL / OCSP:ๆ่ญๆค้ท่็ทไธๆฅ่ฉข
- ๅ ซ、PKI ็ถญ่ญท:CA ๅไปฝ、้้ฐไฟ่ญท、ๆ่ญๅฐๆ
- ไน、้ฏ่ชคๆๆฅ่่จบๆท
- ๐ ๅปถไผธ้ฑ่ฎ
ไธ、AD CS ่ไผๆฅญ PKI ๆถๆงๆฆๅฟต
AD CS ๆฏ Windows Server ็ PKI ๆๅ,่ฒ ่ฒฌ:
- ็ฐฝ็ผๆ่ญ(Issue Certificates)
- ๆค้ทๆ่ญ、็ผๅธ CRL
- ๆ่ญ็ฏๆฌ、็ณ่ซ่ฆๅ、ไฝฟ็จ่ ๆๆฌ
- ๆดๅ Active Directory,่ชๅๆดพ็ผๆ่ญ(Auto-Enrollment)
ไผๆฅญไธญๅธธ็จๆ่ญ็จ้ๅ ๆฌ:
- Windows Server / IIS HTTPS
- SMB ็ฐฝ็ฝฒ / LDAP over SSL
- Wi-Fi 802.1X(EAP-TLS)
- VPN(SSTP、OpenVPN、FortiGate、IPsec)
- SQL Server / Exchange
ๅฎๆด PKI ๆถๆง็คบๆ:
Root CA(้ข็ท)
│
▼
Issuing CA(็ทไธ)
│
├── ไฝฟ็จ่
ๆ่ญ(User / SmartCard)
├── ้ป่
ฆๆ่ญ(Computer / Workstation)
├── ไผบๆๅจๆ่ญ(Web / RDP / LDAP)
└── ็ถฒ่ทฏๆ่ญ(EAP-TLS / VPN)
ไบ、PKI ่ง่ฒ:Root CA、Sub CA、Issuing CA
ๅปบ่ญฐไผๆฅญ็ฐๅขๆก็จๅ ฉๅฑคๆถๆง:
1. Root CA(้ข็ท)
- ๅช็จไพ็ฐฝ็ผ Sub CA(Issuing CA)ๆ่ญ
- ๅนณๆไธ้ๆฉ、ไธไธ็ถฒ、ไธๅ ๅ ฅ AD
- ้้ฐๅฎๅ จๆงๆฅต้ซ
2. Issuing CA(็ทไธ)
- ็ดๆฅ็ฐฝ็ผๆๆไฝฟ็จ่ ่ไผบๆๅจๆ่ญ
- ๆดๅ AD、GPO,่ชๅๆดพ็ผๆ่ญ
- ๆฅๅธธ็้็ CA
ๅฆๆๅ ฌๅธ่ฆๆจกๅฐ(็ด 50 ไบบๅ ง),ๅฏๅ ่จฑไฝฟ็จๅฎๅฑค Enterprise Root CA(ๆฌๆ็คบ็ฏๆญคๆถๆง)。
ไธ、ๅฎ่ฃ AD CS:Enterprise Root CA
1. ๅฎ่ฃ AD CS ่ง่ฒ
# Windows Server GUI ๆไฝ
Server Manager → Add Roles and Features → Active Directory Certificate Services
ๅพ้ธ:
✓ Certification Authority
✓ Certification Authority Web Enrollment(ๅฏ้ธ)
2. ่จญๅฎ AD CS
่ง่ฒๅฎ่ฃๅฎๆๅพ,ๅท่ก「Configure AD CS」。
- CA ้กๅ:Enterprise CA
- ๅฑค็ด:Root CA
- ้้ฐ้ทๅบฆ:ๅปบ่ญฐ 4096 bit
- Hash ๆผ็ฎๆณ:SHA256
- CA ๆๆๆ้:10–20 ๅนด(ไพไผๆฅญๆฟ็ญ)
3. ๆชขๆฅ CA ๆฏๅฆ้ไฝๆญฃๅธธ
certsrv.msc → Certification Authority
ๆฅ็:
✓ CA ๅๅๆๅ
✓ ็ก Error
✓ CRL ๅทฒ็ผๅธ
ๅ、ๆ่ญ็ฏๆฌ(Certificate Template)่จญ่จ
ๅจไผๆฅญ้ไฝไธญ,ไธๆๆๅ็บๆฏๅฐ้ป่ ฆ็ณ่ซๆ่ญ,่ๆฏ้้ๆ่ญ็ฏๆฌ(Certificate Template)็ตฑไธ็ฎก็้กๅ่ๅฑฌๆง。
ๅธธ่ฆ็ฏๆฌ:
- Computer(้ป่ ฆๆ่ญ)
- User(ไฝฟ็จ่ ๆ่ญ)
- Web Server(HTTPS)
- Smart Card Login / EAP-TLS(Wi-Fi)
1. ๅปบ็ซ็ฏๆฌ(ไปฅ Computer ็ฏๆฌ็บไพ)
certtmpl.msc → ๅณ้ต่ค่ฃฝ "Computer" → ๆฐ็ฏๆฌๅฝๅ็บ "Corp-Computer-Cert"
2. ่จญๅฎๅฎๅ จๆง(Security)
- ๅ ่จฑ Domain Computers:Enroll + Autoenroll
3. ็ผไฝ็ฏๆฌ
certsrv.msc → Certificate Templates → New → Certificate Template to Issue
้ธๅ:
✓ Corp-Computer-Cert
ไบ、Auto-Enrollment ่ชๅๆดพ็ผๆ่ญ(ไฝฟ็จ GPO)
1. ๅปบ็ซ GPO
gpmc.msc → Create GPO → "PKI Auto Enrollment"
2. ๅ็จ่ชๅๆ่ญๆดพ็ผ
Computer Configuration →
Policies →
Windows Settings →
Security Settings →
Public Key Policies →
Certificate Services Client – Auto-Enrollment →
✓ Enabled
✓ Renew expired certificates
✓ Update certificates
✓ Enroll certificates automatically
3. ๅฅ็จๅฐ OU
ๅฐ GPO ๅฅ็จ่ณ:
OU = Workstations
OU = Servers
4. ็ซๅณ้ฉ่ญ
gpupdate /force
certmgr.msc → ๆฏๅฆๅบ็พ "Corp-Computer-Cert"
ๅ ญ、ๆๅๆ็จ:HTTPS、RDP、SMB、EAP-TLS
1. IIS / HTTPS ๆ่ญ
็ถฒ็ซๅฎๅ จๅ ๅฏ、ๅๅไปฃ็、API Server ้ฝ้่ฆ Web Server ๆ่ญ。
IIS Manager →
Server Certificates →
Create Domain Certificate →
้ธๆ CA →
ๅฎๆๅพ็ถๅฎ HTTPS ๅ ๅฃ(443)
2. RDP ๆ่ญ(ๅไปฃ่ช็ฐฝ RDP ๆ่ญ)
gpedit.msc →
Computer Configuration →
Administrative Templates →
Windows Components →
Remote Desktop Services →
Remote Desktop Session Host →
Security →
้ธๆๆ่ญ:Corp-Computer-Cert
3. SMB ็ฐฝ็ฝฒ(SMB Signing / LDAP over SSL)
ไฝฟ File Server / AD DS ่ง่ฒๆไพๆดๅฎๅ จ็ๅ ๅฏ。
4. Wi-Fi EAP-TLS(802.1X + NPS)
ๆๅฎๅ จ็ไผๆฅญ Wi-Fi ่ช่ญๆนๅผ:
- ็กๅฏ็ขผ、็กๅฏ้ๆพๆปๆ
- ็ตๅ Auto-Enrollment ๅ จ่ชๅ็ผๆ่ญ
NPS → RADIUS Server
ๆ่ญ:Server ่ Client ๅไฝฟ็จ AD CS ็็ฏๆฌ
AP → ่จญๅฎ 802.1X(WPA2-Enterprise)
Client → ๅฎ่ฃ/่ชๅๅๅพๅไบบๆ่ญ(EAP-TLS)
ไธ、CRL / OCSP:ๆ่ญๆค้ท่็ทไธๆฅ่ฉข
ๅฎๅ จๆฟ็ญ้่ฆๅฏ「ๆค้ท」ๆ่ญ,ไพๅฆ:ๅกๅทฅ้ข่ท、่ฃ็ฝฎ้บๅคฑ。
1. ๆค้ทๆ่ญ
certsrv.msc → Issued Certificates → ๅณ้ต Revoke
2. ็ขบไฟ CRL ๅฏ่ขซ Client ๅญๅ
ไผๆฅญๅธธไฝฟ็จ:
- CRL Distribution Point(CDP):HTTP
- AIA:HTTP
Server Manager → Add Roles → Active Directory Certificate Services →
✓ Online Responder
ๅ ซ、PKI ็ถญ่ญท:CA ๅไปฝ、้้ฐไฟ่ญท、ๆ่ญๅฐๆ
1. ๅไปฝ CA ้้ฐ่่ณๆๅบซ
certutil -backupkey C:\CA-Backup
certutil -backupdb C:\CA-Backup
2. ๆ่ญๆๆๆ้่ๆดๆฐ
ไผๆฅญๆๅปบ็ซ「ๆ่ญๅฐๆ็ฃๆง」,ไพๅฆ SQL、IIS、NPS ็ญๆๅ็ๆ่ญ。
3. AD CS ็งปๆฉ / ็ฝ้ฃๅพฉๅ
ๅ ้:CA ้้ฐ、CA Database、CA ่จญๅฎ。
ไน、้ฏ่ชคๆๆฅ่่จบๆท
1. ๆ่ญๆฒๆ่ชๅๆดพ็ผ
- GPO ๆฒๅฅ็จ
- ็ฏๆฌๆชๅ ่จฑ Autoenroll
- CA ๆช Publish ็ฏๆฌ
2. HTTPS ็กๆณ็ถๅฎๆ่ญ
- ็ผบๅฐ Private Key
- ๆ่ญ็ก Server Authentication EKU
3. Wi-Fi EAP-TLS ็กๆณ็ปๅ ฅ
- Client ๆชๅๅพๅไบบๆ่ญ
- NPS ๆชๅฎ่ฃ Server ๆ่ญ
๐ ๅปถไผธ้ฑ่ฎ
- ๐ก Windows AD Domain Controller ๆถ่จญๆๅญธ
- ๐งฉ Windows DNS Server ๅฎๆดๆๅ
- ๐ก Windows DHCP Server ๆถ่จญๆๅญธ
- ๐ Linux Nginx HTTPS ๆๅญธ
— WWFandy・Windows PKI ็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ