Internal certificates from Windows CA
Copy link to the page “Internal certificates from Windows CA”The Windows CA source issues certificates from your own Active Directory Certificate Services (AD CS). The appliance creates the key and the CSR, the service agent on a Windows server sends the request to the CA with certreq, and the rules renew and install the certificate like any other. During issuance the private key stays on the appliance, and the agent only gets the CSR. The key goes to a server when a rule installs the certificate, and it can be exported under the private key export policy.
When you need this
Copy link to the section “When you need this”- Servers and services with internal names, which a public CA will not issue for, need certificates that the domain’s machines trust.
- You already have an AD CS, and the certificates should keep coming from it, but be renewed and installed automatically.
Requirements
Copy link to the section “Requirements”| Requirement | Details |
|---|---|
| Licence | Enterprise and the Windows CA add-on, which FairSSL enables on the licence. Contact FairSSL to get it |
| Module | The Windows CA module is downloaded and activated under Modules (modules) |
| Service agent | An approved service agent on a Windows server that can reach the CA (Windows servers) |
| Permission on the template | The computer account of the agent’s server, DOMAIN\SERVER$, has Read and Enroll on the template |
| Template | The template is published on the CA under Certificate Templates and allows “Supply in the request” |
| Key type | RSA 2048, 3072 or 4096 bit, or ECDSA P-256 or P-384. Templates with schema version 1 take RSA only |
The service agent runs as LocalSystem, so the CA checks the permissions of the server’s computer account. If the server is a domain controller, the account is a member of Domain Controllers, not Domain Computers.
The default WebServer template gives only Domain Admins and Enterprise Admins the Enroll permission. Make a copy of the template, or give the computer account Enroll on the one you use.
Create the source
Copy link to the section “Create the source”-
Activate the module: open Modules, click Download licensed modules and updates, then Aktiver next to Windows CA, and finally Restart and apply. The Aktiver button is shown in Danish. The restart applies to the application on the appliance, not to the virtual machine.
-
Open Sources › Sources, click Add source and choose Windows CA.
-
Choose the agent under Service agent.
-
Click Find CAs through the agent under CA configuration (Server\CA name), and choose the CA. The answer arrives when the agent next checks in. If the CA is not found, choose Another CA (type it) and enter it as
Server\CA name, for exampleDC19.corp.local\Corp CA. -
Click Fetch templates through the agent under Template, and choose the template. For each template the list shows Subject supplied in the request, SAN allowed, Issued without approval, Minimum key size, Validity and Usage (EKU). If you type the name yourself with Another template name (type it), use the template’s name, not its display name: letters, digits, hyphens and underscores.
-
Save the source.
The page warns if the template builds the subject from Active Directory, if it does not allow a SAN, or if it requires approval by a certificate manager. A template that requires approval makes the source wait until the request has been approved on the CA.
Use the source in a profile
Copy link to the section “Use the source in a profile”-
Open Profiles and click Create certificate profile (create a profile).
-
Give the profile a name, for example
Internal Windows CA, and click Add next to the Windows CA source. -
Choose an RSA key type as the Default key type, and click Create profile.
-
Create the rule as in step 8, and choose the profile you just created under Profile.
Issuance happens in the background. The appliance looks for an answer every 5 minutes. Requests waiting for approval on the CA are checked every 15 minutes for up to a week. Check now sends the request at once.
Check that it works
Copy link to the section “Check that it works”- The source shows Windows CA request with the status Issued and the Request ID on the CA. The same Request ID is listed under Issued Certificates in the Certification Authority console on the CA.
- The certificate is listed under Certificates › Managed by sslbrain.
- Check that the server delivers the certificate, as described in step 8.
If it fails
Copy link to the section “If it fails”The source shows the reason under The last request failed. The most common:
| The source says | Do this |
|---|---|
| The CA or Active Directory refused the agent access | Give the computer account of the agent’s server Read and Enroll on the template, and the right to request certificates on the CA |
| The CA does not issue from this template | Add the template under Certificate Templates on the CA, or choose a template the CA issues from |
| The CA denied the request | The reason is under Failed Requests on the CA |
| The service agent has not checked in for more than 15 minutes | Check that the SSLBrainAgent service is running on the server |
| The service agent refused the task before the script ran | The agent cannot verify the module’s scripts, or its version is too low. Update the agent (updates) |
| The service agent checks in but has not reported the task within a day | The reason is in the agent’s log under C:\ProgramData\SSLBrain\logs on the server |
After a failure the source waits an hour. After 3 failures in a row the source goes into error and retries once a day, and the Renewal failed alert is raised. See also Renewal fails.