Ramblings on IT and Security

Tag: CES

Part 5: Building a Highly Available CEP/CES Infrastructure

In the previous parts of this series, I’ve built a working Certificate Enrollment Services infrastructure from the ground up. I installed and configured the Certificate Enrollment Policy Web Service (CEP), the Certificate Enrollment Web Service (CES), and eventually used these services from both domain-joined and workgroup computers to request certificates. So far, every service is a single point of failure. If the CEP server became unavailable, clients could no longer retrieve certificate enrollment policy. If the CES server became unavailable, certificate enrollment through the web service stopped altogether. For a lab environment this is perfectly acceptable. For a production PKI, it usually isn’t.

Fortunately for me, CEP and CES were designed with redundancy in mind, so in this part I’m going to extend the environment with a second CEP and CES server. At the same time, I’m going to introduce dedicated DNS aliases: CEP01, CEP02, CES01, and CES02. Until now, our service URLs have been tied directly to the underlying server names such as lab-srv-03. That works, but it unnecessarily exposes the physical server identity as part of the service configuration. By using aliases instead, we separate the name of the service endpoint from the server hosting it. This also gives us much more flexibility if we later want to replace servers or change the architecture without changing the names clients use to access the services.

Introducing aliases means there is a little more work to do. DNS, TLS certificates, Kerberos SPNs, CEP and CES service URIs, and the published enrollment endpoints all need to agree on the new names.

So, let’s build the redundant environment first. In the next article, we’ll find out how highly available it really is.

Continue reading

Part 4: Using Certificate Enrollment Services in Practice

In the previous parts of this series, I’ve looked at the architecture behind Microsoft Certificate Enrollment Services and built both the Certificate Enrollment Policy Web Service (CEP) and Certificate Enrollment Web Service (CES). At this point, all the server-side components are in place. But having a working CEP and CES infrastructure is only half the story. Ultimately, a client needs to know where to retrieve certificate enrollment policy, determine which certificate templates it is allowed to use, discover the appropriate enrollment service, and finally submit a certificate request. That’s what I will show you in this part.

I will configure Windows clients to use our CEP service in two different ways. First, I will use Group Policy, which is the obvious choice for centrally managed domain-joined systems. After that, I will configure the enrollment policy locally, which is useful for individual systems and becomes particularly interesting when working with devices that cannot rely on Active Directory Group Policy. I will then follow the complete process from policy discovery to certificate enrollment and look at what Windows is actually doing behind the scenes.

Continue reading

Part 3: Installing the Certificate Enrollment Web Service (CES)

In the previous article, we deployed the Certificate Enrollment Policy Web Service (CEP) and configured support for Kerberos, Username/Password, and Client Certificate authentication. Clients can now successfully retrieve certificate enrollment policies over HTTPS using the XCEP protocol. However, while the policy infrastructure is now in place, clients still have no way to request certificates.

In this article, I’ll complete the Microsoft Certificate Enrollment Services architecture by deploying the Certificate Enrollment Web Service (CES). I’ll prepare Active Directory, configure a dedicated Group Managed Service Account (gMSA), install IIS, deploy the CES role, configure the supported authentication methods, and validate the deployment using PowerShell. By the end of this article, you’ll have a fully operational Certificate Enrollment Web Service capable of securely processing certificate requests over HTTPS using the WSTEP protocol.

Continue reading

Part 1: Understanding Microsoft Certificate Enrollment Services (CEP & CES)

If you’ve ever worked with Microsoft Active Directory Certificate Services (AD CS), you’ve probably come across the Certificate Enrollment Policy Web Service (CEP) and the Certificate Enrollment Web Service (CES). While Microsoft provides documentation on both services, I often notice that the focus is on how to install them rather than why they exist and how they fit into the bigger picture.

When I started diving into CEP and CES myself, I quickly discovered that understanding the architecture is far more important than simply clicking through an installation wizard. Why are there two separate web services? What problem were they designed to solve? What are XCEP and WSTEP? And when should you actually consider deploying CEP and CES instead of relying on traditional certificate enrollment?

Continue reading

© 2026 Michael Waterman

Theme by Anders NorenUp ↑