You deploy a new certification authority (CA) to a server that runs Windows Server 2016.
You need to configure the CA to support recovery of certificates.
What should you do first?
A. Assign the Request Certificates permission to the user
account that will be responsible for recovering certificates.
B. Configure the Key Recovery Agent templates as a certificate template to issue.
C. Modify the Recovery Agents settings from the properties of the CA.
D. Modify the extension of the OCSP Respon
se Signing template.
References:
http://markgossa.blogspot.co.uk/2017/03/enable-key-archival-in-server-2012-r2.html