Add a Key Recovery Agent (KRA) template to CA

  1. Open command prompt and run the certtmpl.msc command. Right-click on the Key

Recovery Agent template, then select Duplicate Template

image-20251110-091228.png

Figure 44: Certificate Template window

  1. The Properties window opens, showing Compatibility tab. Select appropriate windows version under Certificate Authority and Certificate Recipient drop-down box

image-20251110-091240.png

Figure 45: Compatibility Tab window

  1. Select the General tab. In Template display name, type a name for the template

  2. Select the Request Handling tab, and in Purpose select Encryption and Allow private key to be exported is selected

image-20251110-091252.png

Figure 46: Request Handling window

If you are using Smartcard Authentication, the prompt will go on the PIN Pad device to insert Smartcard and enter the pin. Then press OK button on the PIN Pad.

  1. Select the Issuance Requirement tab, deselect CA Certificate manager approval

  2. Select the Cryptography tab, and in the Provider category select Key storage provider

  3. In Algorithm Name, select the algorithm from the list

  4. Select Requests must use one of the following providers, and in Providers select Utimaco CryptoServer Key Storage Provider only

If CA is on Windows Server Core and you are managing it remotely using certtmpl.msc on a different PC, you need to install the Utimaco CryptoServer Key Storage Provider on the PC that is running certtmpl.msc. Otherwise, the Utimaco CryptoServer provider will not appear.

  1. In Request Hash, select a hash type

  2. From the Security tab, verify if Domain Admins and Enterprise Admins are having Enroll

    Permissions

  3. Select Apply and click OK to save the template settings and close the Certificate Template

    console\

  4. Open the command prompt and run the certsrv.msc command\

  5. Right-click the Certificate Templates node. Select New then select Certificate Template to

    Issue

  6. Select the template created in the above steps and click OK