Configuring CES
The
Install-AdcsEnrollmentWebService
cmdlet configures the Certificate Enrollment Web Service (CES). It is also used to create other instances of the service within an existing installation.- Log in to the CES server usingCESAdminas user name, and then launch PowerShell in administrative mode.Run the commandImport-Module ServerManager.Run the commandAdd-WindowsFeature Adcs-Enroll-Web-Svc.Run the commandInstall-AdcsEnrollmentWebService -ApplicationPoolIdentity -CAConfig "CA1.contoso.com\contoso-CA1-CA" -SSLCertThumbprint "sslCertThumbPrint" -AuthenticationType Kerberos.
- Replace <sslCertThumbPrint> with the thumbprint of the SSL certificate created for the CES server, after deleting the spaces between the thumbprint values.
- ReplaceCA1.contoso.comwith your CA computer name.
- Replacecontoso-CA1-CAwith your CA common name.
Complete the installation by selecting eitherYorA.Launch the IIS Manager Console.In the Connections pane, expand the web server that is hosting CES.ExpandSites, expandDefault Web Site, and then click the appropriate installation virtual application name:contoso-CA1-CA _CES_Kerberos.From the left pane, clickApplication Pools.SelectWSEnrollmentServer, and then from the right pane, clickActions>Advanced Settings.Select the identity field under Process Model.In theApplication Pool Identitydialog, select the custom account, and then typeCESSvcas the domain user name.Close all dialogs, and then recycle IIS from the right pane of IIS Manager Console.From PowerShell, typeiisresetto restart IIS.For CESSvc domain users, enable delegation. For more information, see Enabling delegation.