SSL : Part 1 : Building a Microsoft Certificate Authority for your lab

In the first part in this series, I am going to walk you through setting up a simple Certificate Authority on Windows 2016 Server for a lab environment. If you want to get rid of those annoying warnings every time you open a web session for vCenter, or ESXi or pretty much any VMware product, you have to have a signed and trusted certificate on the web server. Without it, you are required to acknowledge the risk of connecting to the site and then clicking to continuing on to that site. This is particularly painful when you are trying to demo a product like the vROps Tenant App for vCD that has a iFrame that connects to the App. Unless you go and do the acceptances before you start the demo, you are stuck getting rid of these warnings which interrupt proceedings. In my lab environment, I setup a Microsoft Certificate Authority to sign certificates for the various tools I am running allowing me to get rid of that warning and have all green URLs in my browser.

First things first, you need to have a VM running Windows Server 2016. I will not go into the details of setting up a Windows Server here.

Step 1. We need to add the Certificate Authority Role to the server. Open the Server Manager and then select Add Roles and Features.

I wonder.jpg

Step 2. Click Next on the information page.

I wonder_001.jpg

Step 3. Keep role-based or feature-based installation selected and click Next.

I wonder_002.jpg

Step 4. There should only be one destination server and it should be the one you are working on. Click Next.

I wonder_003.jpg

Step 5. Next in the Server Roles selection, tick the Active Directory Certificate Services and wait for the popup for the additional features that are required for ADCS.

I wonder_004.jpg

Once this pops up, click Add Features.

I wonder_005.jpg

Step 6. You should now have a tick against Active Directory Certificate Services. Click Next.

I wonder_006.jpg

Step 7. On the select features page, leave it as is and click Next.

I wonder_007.jpg

Step 8. Click Next on the ADCS information page.

I wonder_008.jpg

Step 9. Select Certification Services in the Role Services and click Next.

I wonder_009.jpg

Step 10. Select Restart the desination server automatically if required and click Yes in the popup. Finally click Install.

I wonder_010.jpg

Step 11. The installation of the ADCS will start.

I wonder_011.jpg

Step 12. If all goes well, the installation should complete and you can click close. (On a fresh 2016 install a restart is not usually required.)

I wonder_012.jpg

Step 13. Go back to your Server Manager Dashboard and you should see a yellow exclamation. This indicates you need to complete the ADCS configuration.

I wonder_013.jpg

Step 14. Click the flag and then click Configure Active Directory Certificate Services on th…. in the Post-deployment Configuration item.

I wonder_014.jpg

Step 15. Keep the default credentials and click Next.

I wonder_020.jpg

Step 16. Tick Certification Authority and click Next.

I wonder_016.jpg

Step 17. Keep Standalone CA selected and click Next. For an Enterprise CA you need to be connected to a domain and that is not needed for our purposes.

I wonder_017.jpg

Step 18. You want to deploy a Root CA unless you have a Root CA that this CA can be a subordinate of. Click Next.

I wonder_018.jpg

Step 19. Leave create new private key selected and click next.

I wonder_019.jpg

Step 20. The default Key Length and algorithm should be sufficient for lab needs. Click Next

I wonder_020.jpg

Step 21. Give the CA a name and click Next.

I wonder_023.jpg

Step 22. The default validity is 5 years. I normally make it 10. Once you have set it, click Next.

I wonder_024.jpg

Step 23. Leave the default database locations unless you specifically want to change them and click Next.

I wonder_025.jpg

Step 24. Click Configure on the summary page.

I wonder_026.jpg

Step 25. And you should now have a configured Certificate Authority.

I wonder_027.jpg

Step 26. On the Server Manager Dashboard, click the Tools Menu and then Certification Authority.

I wonder_028.jpg

Step 27. And here you should see your newly minted CA.

I wonder_029.jpg

Step 28. Right click lab-ca and click Properties. You will see Certificate #0 in the list which is the public certificate for the CA itself. Click View Certificate.

I wonder_030.jpg

Step 29. You will see the summary page for the certificate that indicate the Validity period. (10 years in this case)

I wonder_031.jpg

Step 30. In order for devices you use to trust certificates signed by this Certificate Authority, you will need to install the public certificate of the CA into the Trusted CAs list on each device.
Click the Details tab.

I wonder_032.jpg

Step 31. Now click Copy to File and click Next.I wonder_033.jpg

Step 32. You need to export the certificate in Base-64 Encoded format as you will use the contents for various VMware solutions. Select Base-64 and click Next.

I wonder_034.jpg

Step 33. Select a location and name for the file and click Next.

I wonder_035.jpg

Step 34. Click Finished on the summary page.

I wonder_036.jpg

Step 35. If you now open the file you just saved with Notepad, it will look something similar to this.

I wonder_037.jpg

And that’s it. You are now ready to mint certificates for your lab servers. Don’t forget to save the public certificate into the Trusted Root Certificates of your devices that you use to manage the lab environment.

In part 2 we will look at signing a CSR (Certificate Signing Request) with our new CA.