Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Type "certsrv.msc" and press Enter .to launch the Certification Authority manager

Double-click the name of your server, e.g. "la-DC101-CA" to expand it

...

Find and select the newly created enrolment template, e.g. "PIV Smartcard Enrolment Template for Agent". and then click OK

3.3

...

Add the enrolment template to the Agent's account

Login the

...

agent's account

Right-click the Windows Start button and select Run.

Type "certmgr.msc" and press Enter to launch the Certificate Manager

Image Added

Click on "Certificate \ Personal" to expand it

Image Added

Right click "Certificates \ Personal \ Certificates"

Image Added

Select "All Tasks \ Request New Certificate…"

Image Added

Click "Next"

Image Added

Click "Next"

Image Added

Select the newly created enrolment template, e.g.

Image Removed

  1. Click 'next'

...

  1. Make sure your AD Enrollment Policy, click 'next'

Image Removed

...

'PIV Smartcard Enrolment Template for Agents', and click 'Enroll'

Image Removed

...

Image Added

Click "Finish"

3.4

...

Create a Certificate Logon Template for target users by Agents

  1. In order to be able to issue a smart card certificate on behalf of another user, the Smart Card User or Logon template needs to be adjusted to require the Enrolment Agent certificate for enrolment.
  2. Duplicate and configure a Smart Card User or Logon template.

...