Pro Active Directory Certificate Services: Creating and Managing Digital Certificates for Use in Microsoft Networks
暫譯: 主動式目錄憑證服務:在 Microsoft 網路中創建和管理數位憑證

Hughes, Lawrence E.

  • 出版商: Apress
  • 出版日期: 2022-04-12
  • 售價: $2,090
  • 貴賓價: 9.5$1,986
  • 語言: 英文
  • 頁數: 480
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1484274881
  • ISBN-13: 9781484274880
  • 海外代購書籍(需單獨結帳)

商品描述

In order to deploy and use Microsoft Certificate Services, you need to understand the fundamentals of cryptography, digital signatures, encryption, TLS, and S/MIME. It is also important to understand the concepts behind public key infrastructure (PKI). This book teaches you all the required background knowledge you need. Then it takes you deeper, step by step, teaching you how to deploy Certificate Services and configure it to issue various digital certificate types, complete with examples of using these certificates with IIS, Outlook, and Windows.

Microsoft-based networks—on-premises, hybrid, and cloud-based networks—are used in companies of all sizes. Within them, there are many applications of digital certificates that can be created and managed by Microsoft Certificate Services. As security is more important than ever, and cryptography and PKI are fundamental to so many of these defenses, understanding Microsoft Certificate Services is becoming an increasingly more desirable skill.

Most IT workers don’t realize the many uses and purposes of Certificate Services, especially within a corporate or government agency network, and how tightly integrated they are with the Microsoft Windows Domain style of networks and Active Directory (on-premises or cloud-based, including Azure, AWS, and Google Cloud Services). This book will teach you the gamut.

You will appreciate the learning approach presented in the book, beginning with the basics (cryptographic primitives such as encryption and message digests), getting into combinations of primitives to accomplish specific things (such as digital signatures and envelopes), and then trying real-word systems based on digital certificates and PKI (such as TLS, S/MIME secure email, cryptographic authentication, and more). The book wraps it all up and teaches you how to deploy Certificate Services and issue the various types of certificates, including how they are used.

What You Will Learn

- Understand basic cryptography (symmetric and asymmetric key encryption, message digests, and digital signatures and envelopes)
- Know how TLS, S/MIME, and cryptographic authentication work
- Discover applications of cryptography related to secure servers with TLS and cryptographic (passwordless) authentication to online services including Windows and secure email
- Get to know the common types of digital certificates, how to create and manage them, and examples of their use with IIS, Outlook, etc. 

Who This Book Is For
Microsoft system and network engineers, security engineers, and CISOs. Readers should have familiarity with Windows Server 2019 (or more recent) and Active Directory.

商品描述(中文翻譯)

為了部署和使用 Microsoft 憑證服務,您需要了解加密學、數位簽章、加密、TLS 和 S/MIME 的基本原理。理解公鑰基礎設施(PKI)背後的概念也很重要。本書將教您所需的所有背景知識。然後,它將逐步深入,教您如何部署憑證服務並配置其發佈各種數位憑證類型,並提供使用這些憑證與 IIS、Outlook 和 Windows 的範例。

基於 Microsoft 的網路——本地、混合和雲端網路——被各種規模的公司使用。在這些網路中,有許多數位憑證的應用可以由 Microsoft 憑證服務創建和管理。隨著安全性比以往任何時候都更重要,加密學和 PKI 是這些防禦的基礎,理解 Microsoft 憑證服務正變得越來越重要。

大多數 IT 工作人員並未意識到憑證服務的多種用途和目的,特別是在企業或政府機構的網路中,以及它們與 Microsoft Windows 域風格的網路和 Active Directory(本地或雲端,包括 Azure、AWS 和 Google Cloud Services)之間的緊密整合。本書將教您所有相關知識。

您將會欣賞本書所呈現的學習方法,從基本概念(如加密和訊息摘要等加密原語)開始,進入原語的組合以實現特定功能(如數位簽章和信封),然後嘗試基於數位憑證和 PKI 的實際系統(如 TLS、S/MIME 安全電子郵件、加密身份驗證等)。本書將所有內容整合起來,教您如何部署憑證服務並發佈各種類型的憑證,包括它們的使用方式。

您將學到的內容:

- 理解基本的加密學(對稱和非對稱金鑰加密、訊息摘要、數位簽章和信封)
- 知道 TLS、S/MIME 和加密身份驗證的運作方式
- 發現與安全伺服器相關的加密應用,包括使用 TLS 和無密碼的加密身份驗證來訪問 Windows 和安全電子郵件等在線服務
- 了解常見的數位憑證類型,如何創建和管理它們,以及它們在 IIS、Outlook 等中的使用範例

本書的讀者對象:

Microsoft 系統和網路工程師、安全工程師和首席資訊安全官(CISO)。讀者應對 Windows Server 2019(或更新版本)和 Active Directory 有一定的熟悉度。

作者簡介

Lawrence Hughes is a renowned expert in cryptography and PKI. He previously worked at VeriSign and co-founded and was CTO at CipherTrust (a secure email proxy appliance). He also was employed at Sixscape Communications in Singapore where he was responsible for creating much of their technology. Lawrence founded the US-based company PKIEdu Inc. (Public Key Infrastructure Education) to conduct training and consulting in the area of PKI. He created and taught the courseware at VeriSign (the first leading company in the PKI space) and presented it internationally to affiliates and large customers. He is a security author and was heavily involved in the deployment of several national certification authorities in the UK, Netherlands, and Australia.

作者簡介(中文翻譯)

Lawrence Hughes 是一位著名的密碼學和公鑰基礎設施(PKI)專家。他曾在 VeriSign 工作,並共同創立了 CipherTrust(安全電子郵件代理設備)並擔任首席技術官。他還曾在新加坡的 Sixscape Communications 任職,負責創建其大部分技術。Lawrence 創立了美國公司 PKIEdu Inc.(公鑰基礎設施教育),專注於 PKI 領域的培訓和諮詢。他在 VeriSign 創建並教授課程教材(該公司是 PKI 領域的首家領先公司),並在國際上向合作夥伴和大型客戶進行演示。他是一位安全作者,並在英國、荷蘭和澳大利亞的多個國家認證機構的部署中積極參與。