DC

Active Directory Certificate Services 클릭

Active Directory Certificate Services 클릭

image.png

Install-AdcsCertificationAuthority -CAType EnterpriseRootCA -CACommonName CORP-CA -Force

Certification Authority 클릭

Certification Authority 클릭

Web Server 우클릭 → Duplicate Template 클릭

Web Server 우클릭 → Duplicate Template 클릭

Compatibility

Compatibility

General

General

Request Handling

Request Handling

Security

Security

image.png

Certification Authority 클릭

Certification Authority 클릭

Certificate Templates → New → Certificate Template to Issue 클릭

Certificate Templates → New → Certificate Template to Issue 클릭

ADFS 클릭

ADFS 클릭

Get-Certificate -Template ADFS -SubjectName CN=*.corp.com -DnsName www.corp.com, adfs.corp.com -CertStoreLocation Cert:\\LocalMachine\\My\\
ls Cert:\\LocalMachine\\My\\
Export-PfxCertificate -Cert Cert:\\LocalMachine\\My\\[CN=*.corp.com의 Thumbprint] -Password (ConvertTo-SecureString "Skill39**" -AsPlainText -Force) -FilePath wildcard.pfx
ls Cert:\\LocalMachine\\Root\\
Export-Certificate -Cert Cert:\\LocalMachine\\Root\\[CN=CORP-CA, DC=corp, DC=local의 Thumbprint] -FilePath ca.crt

image.png

image.png

image.png