Skip to content

The Windows CA source issues certificates from your own Active Directory Certificate Services (AD CS). The appliance creates the key and the CSR, the service agent on a Windows server sends the request to the CA with certreq, and the rules renew and install the certificate like any other. During issuance the private key stays on the appliance, and the agent only gets the CSR. The key goes to a server when a rule installs the certificate, and it can be exported under the private key export policy.

  • Servers and services with internal names, which a public CA will not issue for, need certificates that the domain’s machines trust.
  • You already have an AD CS, and the certificates should keep coming from it, but be renewed and installed automatically.
RequirementDetails
LicenceEnterprise and the Windows CA add-on, which FairSSL enables on the licence. Contact FairSSL to get it
ModuleThe Windows CA module is downloaded and activated under Modules (modules)
Service agentAn approved service agent on a Windows server that can reach the CA (Windows servers)
Permission on the templateThe computer account of the agent’s server, DOMAIN\SERVER$, has Read and Enroll on the template
TemplateThe template is published on the CA under Certificate Templates and allows “Supply in the request”
Key typeRSA 2048, 3072 or 4096 bit, or ECDSA P-256 or P-384. Templates with schema version 1 take RSA only

The service agent runs as LocalSystem, so the CA checks the permissions of the server’s computer account. If the server is a domain controller, the account is a member of Domain Controllers, not Domain Computers.

The default WebServer template gives only Domain Admins and Enterprise Admins the Enroll permission. Make a copy of the template, or give the computer account Enroll on the one you use.

  1. Activate the module: open Modules, click Download licensed modules and updates, then Aktiver next to Windows CA, and finally Restart and apply. The Aktiver button is shown in Danish. The restart applies to the application on the appliance, not to the virtual machine.

  2. Open Sources › Sources, click Add source and choose Windows CA.

  3. Choose the agent under Service agent.

  4. Click Find CAs through the agent under CA configuration (Server\CA name), and choose the CA. The answer arrives when the agent next checks in. If the CA is not found, choose Another CA (type it) and enter it as Server\CA name, for example DC19.corp.local\Corp CA.

  5. Click Fetch templates through the agent under Template, and choose the template. For each template the list shows Subject supplied in the request, SAN allowed, Issued without approval, Minimum key size, Validity and Usage (EKU). If you type the name yourself with Another template name (type it), use the template’s name, not its display name: letters, digits, hyphens and underscores.

  6. Save the source.

The page warns if the template builds the subject from Active Directory, if it does not allow a SAN, or if it requires approval by a certificate manager. A template that requires approval makes the source wait until the request has been approved on the CA.

  1. Open Profiles and click Create certificate profile (create a profile).

  2. Give the profile a name, for example Internal Windows CA, and click Add next to the Windows CA source.

  3. Choose an RSA key type as the Default key type, and click Create profile.

  4. Create the rule as in step 8, and choose the profile you just created under Profile.

Issuance happens in the background. The appliance looks for an answer every 5 minutes. Requests waiting for approval on the CA are checked every 15 minutes for up to a week. Check now sends the request at once.

  • The source shows Windows CA request with the status Issued and the Request ID on the CA. The same Request ID is listed under Issued Certificates in the Certification Authority console on the CA.
  • The certificate is listed under Certificates › Managed by sslbrain.
  • Check that the server delivers the certificate, as described in step 8.

The source shows the reason under The last request failed. The most common:

The source saysDo this
The CA or Active Directory refused the agent accessGive the computer account of the agent’s server Read and Enroll on the template, and the right to request certificates on the CA
The CA does not issue from this templateAdd the template under Certificate Templates on the CA, or choose a template the CA issues from
The CA denied the requestThe reason is under Failed Requests on the CA
The service agent has not checked in for more than 15 minutesCheck that the SSLBrainAgent service is running on the server
The service agent refused the task before the script ranThe agent cannot verify the module’s scripts, or its version is too low. Update the agent (updates)
The service agent checks in but has not reported the task within a dayThe reason is in the agent’s log under C:\ProgramData\SSLBrain\logs on the server

After a failure the source waits an hour. After 3 failures in a row the source goes into error and retries once a day, and the Renewal failed alert is raised. See also Renewal fails.