Skip to main content

XProtect Certificates guide

Certificates guide for Milestone XProtect products

Last Updated: 1 minute read
Versionver3
LanguageEnglish

This guide gives you an introduction to encryption and certificates, together with step-by-step procedures on how to install certificates in a Windows Workgroup environment.

Milestone recommends that you establish a Public Key Infrastructure (PKI) for creating and distributing certificates. A PKI is a set of roles, policies, hardware, software, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates and manage public-key encryption.

In a Windows domain, it's recommended to establish a PKI using the Active Directory Certificate Services (AD CS). If you are unable to build a PKI, such as when different domains lack trust or you have not domains, you can manually create and distribute certificates. Manual distribution is not secure. If you choose this method, you are responsible for always keeping the private certificates secure. Protecting the certificates reduces the risk of attacks on client computers that trust the certificates.