Home / Blog / Recast Blog / The Homelab Series – Step 2: Adding a Certificate Authority 

The Homelab Series – Step 2: Adding a Certificate Authority 

On Jan 16, 2026 by Marty Miller Marty Miller
5 min

Creating a Certificate Authority and understanding how Certificates work with ConfigMgr, Intune, and the Recast Management Server are essential to establishing a secure infrastructure.   

Creating a Certificate Authority is very straightforward. For this example, we are adding the Certificate Authority to our Domain Controller. 

Creating the Certificate Authority

  1. Begin by adding the Certificate Authority role. 
    • Install-WindowsFeature ADCS-Cert-Authority -IncludeManagementTools 
  2. After the role is added, click to configure Active Directory Certificate Services on the destination server. 
    • Make sure the credentials shown are part of the Local Administrators Group (Domain Admin since we are on a DC) and the Enterprise Admins group. Select Next.  
Creating a Certificate Authority - Configure ADCS
Creating a Certificate Authority - Credentials
  1. Select Certification Authority and click Next
Creating a Certificate Authority - CA Role Services
  1. Select Enterprise CA and click Next
Creating a Certificate Authority - CA Setup Type
  1. Select Root CA and click Next
Creating a Certificate Authority - CA Type
  1. Select Create New Private Key and click Next
Creating a Certificate Authority - Private Key
  1. Cryptography for CA can stay at the defaults. Click Next
Creating a Certificate Authority - Cryptographic options
  1. CA Name can stay at the defaults. Click Next.
Creating a Certificate Authority - CA Name
  1. Specify the Validity period can stay at five years and click Next
Creating a Certificate Authority - Validity Period
  1. CA Database can stay as –is. Click Next
Creating a Certificate Authority - Certificate database locations
  1. For Confirmation, click Configure
Creating a Certificate Authority -  Confirmation screen
  1. For Results, verify that the configuration succeeded and click close
Creating a Certificate Authority - Successful configuration

Now that the CA has been set up and configured, we are going to create a certificate template that will be used with our Recast Management Server (and can be used with any web server in your environment). 

Certificate Template

  1. Load the Certification Authority from the Windows Menu. 
Creating a Certificate Authority - Certification Authority
  1. Drop down the homelab-DC-CA computer and right click on Certificate Templates. Select Manage
Creating a Certificate Authority - Manage certificate templates
  1. Scroll down to the “Web Server” Template and right click. We are going to make a duplicate. 
Creating a Certificate Authority - Duplicate web server template
  1. Let’s change the name under the “General” tab to “Recast Web Server.” Just for fun, change the validity period to five years. 
  1. Under “Security” add the “Web Server Cert Enrollment” group and allow Enroll and Autoenroll. Additionally, you can add the Certificate Admins Group to allow users to enroll the new certificate. There’s no need to select Autoenroll for this group. 
Creating a Certificate Authority - Web server cert enrollment permissions
  1. The Web Server Cert Enrollment group should contain any devices that might need to create a certificate. Because they are set to Auto Enroll, they will automatically create a certificate for themselves from the template. Here is a list of which computers I have added to the group. 
Creating a Certificate Authority - Enrollment properties
  1. The Certificate Admins group can be used to allow people to enroll the new certificate. 
Creating a Certificate Authority - Certificate admins
  1. Finally, under the Subject Name tab, select Build from Active Directory Information and select the Subject Name Format as “Fully Distinguished Name.” Select DNS Name and User Principal Name (UPN)
Creating a Certificate Authority - New template properties
  1. Click Apply 
  1. You can close the window, keeping the Certsrv window open. 
  1. Right click on the Certificate Templates section and select New -> Certificate Template to Issue.  
Creating a Certificate Authority - Certificate template issuance
  1. In the Enable Certificate Templates window that opens, select Recast Web Server and click OK

Request a Certificate

You can now log into the server that will become your RMS server and request to create a certificate using Manage Computer Certificates. 

Creating a Certificate Authority -  Manage computer certificates
  1. In the Personal right click and choose All Tasks then Request New Certificate
Creating a Certificate Authority - Request new certificate
  1. Certificate Enrollment window will open. Select Next
  1. Select Active Directory Enrollment Policy and click Next
Creating a Certificate Authority - Cert enrollment policy
  1. In the Request Certificates window select Recast Web Server and click Enroll
Creating a Certificate Authority - AD enrollment policy
  1. You should see that the status is Succeeded. Click Finish
  1. In the Certificate Manager, you should now see a certificate issued to RMS. 
Creating a Certificate Authority - RMS Certificate

That’s the end of the setup for the Certificate Authority ConfigMgr will use it to create certs, and if you choose to set up the RMS you can use the cert we just created to secure the site.  

In the next blog of this series, we will set up the Routing server to connect the environment to the internet. It’s a completely optional step but knowing how to do this is a good addition to your toolkit. 

Next steps  

Make your homelab more powerful. Download our free tools to help you automate, troubleshoot, and validate configurations in your test environment. 

Share