Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

3.2 Adding the Template to the Certification Authority

Right-click the Windows Start button and select Run.

Type "certsrv.msc" and press Enter.

...

Image Added

Double-click the name of your server,

...

e.g. "la-DC101-CA" to expand it

Image Added

Right-click Certificate Templates

Image Added

Select New and then select Certificate Template to Issue.

Image RemovedImage Added

...

Find and select the

...

newly created

...

enrolment template, e.g. "PIV Smartcard Enrolment Template for Agent". and then click OK

Image Removed Image Added

3.3 Issue Enrolment Certificate template to Agent

...

Enroll a Smart Card Certificate on behalf of others

    1. Log in as the user that will do enrollment for others, then run certmgr.msc. Right click the Certificate – Current User / Personal / Certificate, and select "Enroll on behalf of" from All Tasks / Advanced Operations.

    1. Click through the "Before You Begin" screen, and on the "Certificate Enrollment" screen, click the "Browse…" button and select the enrollment agent certificate you have been issued in Step 3.1 .




Click 'OK'.

    1. Note: If no Enrollment Agent certificate is available you will need to request one be issued to you.



    1. On the next page select the smart card enrollment certificate template, ie. PIV Smartcard Logon Template for Agents.

    1. Click Next and enter the target domain user you are going to enroll the certificate on the behalf of.

    1. Click Next, and it asks you to insert the user's smart card if it is not already inserted. Enter the PIN. Image Modified
    2. If the enrollment is successful, the dialog will show the following:




    1. After the enrollment is success, the smart card is ready for target user, and Agent can click 'Next user' to enroll for others or close windows.
    2. You can see the issued smartcard is listed in Agent's personal store.

    1. Now, the smart card sign-in is ready for end user, and user is able to login domain with the issued smartcard.