Microsoft recommends that you do not deploy a Root Certification Authority (CA) on a Domain Controller.
INSTALL SMART CARD SERVICE WINDOWS 7 WINDOWS
For information about implementing advanced configurations, see this Microsoft Technet article ( (v=ws.10).aspx).Ä«efore you create a Certification Authority (CA), be sure you set up a Microsoft Windows Active Directory domain environment. These instructions include steps for a basic configuration. IMPORTANT: The installation should be performed by an experienced system administrator. NOTE: If a Certification Authority already exists in your environment, skip this chapter and proceed to YubiKey Minidriver Installation. These steps assume an Active Directory environment is already stood up and configured. This chapter covers the basic configuration for setting up a new Certification Authority (CA) to a Windows Server (2012 R2 and above).
![install smart card service windows 7 install smart card service windows 7](https://duo.com/assets/img/documentation/rdp/rdp-whitelist-credprov_2x.png)
In order to utilize the Smart Card functions in a Windows environment using the YubiKey Minidriver, a Certification Authority (CA) must first be stood up.
![install smart card service windows 7 install smart card service windows 7](https://www.acs.com.hk/en/download-product-image-library/1667/20121227172337acr33u_sidecard.png)
![install smart card service windows 7 install smart card service windows 7](https://i.ytimg.com/vi/RgYrFNC-Nss/mqdefault.jpg)
Adding ECC Through a Group Policy Object.Adding Support for Elliptic Curve Cryptography (ECC) Certificate Login.Configuring a Certification Authority (CA) for Smart Card Authentication.