> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/ja/zheng-ming-shu-guan-li/domain-controller-certificates.md).

# Domain Controller 証明書

{% hint style="info" %}
この機能にはバージョンが必要です **1.6** 以降が必要です。

代わりに、当社の [Active Directory](/ja/zheng-ming-shu-guan-li/active-directory.md) エンドポイントの使用を検討してください。
{% endhint %}

{% hint style="warning" %}
SCEPman Enterprise Edition のみ
{% endhint %}

SCEPman を使用して、ドメイン コントローラーに Kerberos 認証証明書を発行できます。これにより、AAD またはハイブリッド参加済みデバイスは、オンプレミス リソースへのアクセス時にシームレスに認証できます。これは、Hybrid Key trust for Windows Hello for Business の実装に使用できます。 **Hybrid Key trust for Windows Hello for Business**。SCEPman は必要条件を置き換えます **公開鍵基盤**。詳細は [こちら](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust-prereqs)

## Enhanced Key Usage (EKU) 拡張のない Root CA

**この機能では Root CA に新しい要件があります。**\
以前のバージョンから更新する場合は **1.6** 、 **新しい** Root CA を生成する必要があります。\
Kerberos 認証証明書をサポートするには、CA 証明書に Enchanced Key Usage (EKU) 拡張が含まれていないか、Kerberos Authentication と Smart Card Logon を含める必要があります。

SCEPman から始める場合は **1.6** 、および SCEPman で Root CA を生成する場合は、以下の手順を省略できます。\
それ以外の場合は、このガイドに従って新しい Root CA を生成してください。

{% hint style="warning" %}
新しい CA 証明書を生成した場合は、Intune ポリシーを更新し、新しい Root CA と新しいユーザー証明書およびデバイス証明書を展開する必要があります！
{% endhint %}

1. 次の場所に移動します **Key Vault**
2. ユーザー アカウントが次に追加されているか確認してください **アクセス ポリシー** すべての証明書権限付きで
3. 次へ移動し **Certificates**を選択し、CA 証明書をクリックして **Delete**
4. CA 証明書の削除が成功したら、次をクリックする必要があります **Manage deleted certificates**
5. 手順 3 で削除した CA 証明書を選択し、次をクリックします **Purge** （証明書を完全削除すると復元できないことに注意してください！）
6. SCEPman App Services を今すぐ再起動してください
7. App Services が再起動したら、SCEPman URL に移動して SCEPman Dashboard を開きます
8. セクション **Config issues**が表示されますので、このセクションの手順に従ってください。
9. 新しい CA 証明書を生成した後、SCEPman Dashboard で CA の適合性を確認できます。

SCEPman Dashboard での CA 適合性:

![](/files/ce47a16b32724ac281035c1e06cb7229fd5643d5)

## SCEPman サービスの構成変更

機能を有効にするには、SCEPman サービスに 2 つのアプリケーション設定を追加する必要があります。現在の実装では、DC 要求に事前共有キー（パスワード）を使用します。\
**新しいキー/パスワードを生成し、安全な場所に保管してください。** （後続の手順および後で domain Controllers で必要になります）

1. 移動先 **App Services**
2. 次に、SCEPman アプリを選択します
3. 次に、 **Settings** をクリックします **Environment variables**
4. 追加を選択します
5. 種類 **AppConfig:DCValidation:Enabled** 名前として（Linux ベースの SCEPman では : の代わりに \_\_ を使用してください）
6. 種類 **true** 値として
7. で確定 **OK**
8. 選択します **追加** 再度
9. 種類 **AppConfig:DCValidation:RequestPassword** 名前として（Linux ベースの SCEPman では : の代わりに \_\_ を使用してください）
10. 次の **キー/パスワードを**、以前生成したものを値として入力します
11. で確定 **OK**
12. アプリケーション設定を保存します

## Kerberos Authentication 用にドメイン内で CA 証明書を信頼する

Kerberos authentication に使用される証明書は、認証 CA 証明書として AD ドメイン内で信頼されている必要があります。SCEPman Dashboard から CA 証明書をダウンロードしてください。ファイルを `scepman-root.cer`として保存した場合は、Enterprise Administrator 権限を持つアカウントで次のコマンドを使用して SCEPman CA 証明書（Root CA でも Intermediate CA でも可）を公開できます:

```
certutil -f -dsPublish scepman-root.cer NTAuthCA
```

同様に、次のコマンドを実行して Root CA 証明書（つまり SCEPman CA 証明書、または SCEPman が Intermediate CA の場合は SCEPman CA 証明書チェーンの Root CA）を AD Forest 内のすべてのマシンの Trusted Root 証明書ストアにプッシュします:

```
certutil -f -dsPublish scepman-root.cer RootCA
```

その後、CA 証明書は一般的に AD で信頼され、特に Kerberos Authentication で信頼されます。ただし、すべてのデバイスにこの構成が届くまでにはある程度時間がかかります（デフォルト構成では最大 8 時間）。任意のマシンで `gpupdate /force`を実行すると、このプロセスを短縮できます。たとえば domain controllers で。

これにより、DC 証明書がドメイン内で信頼されることが保証されます。また、Root CA 証明書を配布する Trusted Certificate プロファイルの対象内にあるすべての Intune 管理デバイスでも信頼されます。すべてのシステムで DC 証明書を信頼させるには、アプライアンスやクラウド サービスなどの他のサービスに Root CA を手動で配布する必要がある場合があります。

## クライアントへのインストール

次に、当社のオープンソース SCEP クライアント ソフトウェア [SCEPClient](https://github.com/scepman/scepclient/releases)をダウンロードする必要があります。サフィックス *-framework* が付いたリリースは .NET Framework 4.6.2 を使用します。これは Windows Server 2016 に事前インストールされており、より新しいバージョンと互換性があります。その他のリリースでは、ターゲット システムに .NET Core Runtime をインストールする必要があります。

SCEPman から Domain Controller 証明書を受け取るには、Domain Controller で昇格されたコマンド プロンプトから次のコマンドを実行します:

```
ScepClient.exe newdccert https://your-scepman-domain/dc RequestPassword
```

前のコマンドに SCEPman URL を追加する必要がありますが、パスはそのままにしてください `/dc`を置き換えます `RequestPassword` を、以前生成した安全なキー/パスワードに。

要求パスワードは SCEPman の CA 証明書で暗号化されるため、SCEPman だけが読み取れます。Domain Controller 証明書は、正しい要求パスワードでのみ発行されます。

### 証明書の自動更新

{% hint style="warning" %}
上記のコマンドは、すでに有効な証明書があるかどうかにかかわらず、新しい DC 証明書を要求します。既存の証明書の有効期限が切れそうな場合にのみ証明書を更新する方法については、次のセクションを参照してください。
{% endhint %}

完全に自動化された証明書更新のためには、ScepClient を **すべての** domain controllers に、PowerShell スクリプト [enroll-dc-certificate.ps1](https://github.com/scepman/scepclient/blob/Core31/enroll-dc-certificate.ps1)とともに配布する必要があります。次のコマンドを SYSTEM コンテキストで実行するスケジュール済みタスクを追加します（URL と要求パスワードを調整してください）:

```
powershell -ExecutionPolicy RemoteSigned -File c:\scepman\enroll-dc-certificate.ps1 -SCEPURL https://your-scepman-domain/dc -SCEPChallenge RequestPassword -LogToFile
```

PowerShell スクリプトが SCEPClient.exe およびその追加の依存関係と同じディレクトリにあることを確認してください。

![スケジュール タスクでの実行アクションの構成](/files/d6d864ce022915b44c3562224b3a763e27f972d3)

これは、マシン ストア内の既存の DC 証明書を確認します。少なくとも 30 日の有効期間がある適切な証明書がない場合にのみ、ScepClient.exe を使用して SCEPman に新しい DC 証明書を要求します。30 日のしきい値を変更したい場合は、PowerShell スクリプトの -ValidityThresholdDays パラメーターを使用してください。

スクリプトは、保存されているディレクトリに継続的なログ ファイルを書き込みます。このログ ファイルが不要な場合は、 `-LogToFile` パラメーターを省略してください。代わりに、Information、Error、および/または Debug ストリームをファイルにリダイレクトできます（例: `6>logfile.txt 2>&1`).

WHfB では、2016 以降のバージョンで動作するすべての DC に Kerberos Authentication 証明書が必要です。古い DC は認証要求を新しい DC に転送するため、必ずしも Kerberos Authentication 証明書を必要としません。ただし、証明書を与えることもベスト プラクティスです。

### 既存の内部 PKI の段階的廃止

Internal PKI が SCEPman と並行して DC 証明書（証明書テンプレート "Domain Controller"、"Domain Controller Authentication"、および "Kerberos Authentication"）を登録しないようにしてください。そうしないと、DC は Internal PKI の DC 証明書を使用する可能性があり、たとえば CDP に到達できない場合には信頼されないと見なされます。SCEPman の DC 証明書は、上記のテンプレートの証明書が使用できるすべての用途、たとえば Kerberos 認証および LDAPS に使用できます。

これを実現する最も簡単な方法は、内部 CA による "Domain Controller"、"Domain Controller Authentication"、および "Kerberos Authentication" テンプレートへの証明書発行を停止することです。Certification Authority MMC Snap-In で、各 Internal CA の発行済みテンプレートの一覧からこれらのテンプレートを削除します。その後、Internal CA からすでに発行された証明書を、ドメイン コントローラーの "MY" ストアから削除します（`certlm.msc` を開き、Personal に移動します）。 `gpupdate /force`その後でも、Internal PKI から新しい DC 証明書が DC の Personal ストアに表示されるべきではありません。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/ja/zheng-ming-shu-guan-li/domain-controller-certificates.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
