Configure the CA to support Key Archival

  1. Open the command prompt and run the certsrv.msc command

  2. Right click CA Name and select Properties

  3. Select the Recovery Agent tab

image-20251110-092106.png

Figure 54: Recovery Agents Tab window

  1. Select the radio button for Archive the key

  1. Click Add

image-20251110-092120.png

Figure 55: Key Recovery Agent Selection window

  1. Select the KRA certificate you just issued and Click OK

  1. Click OK

  1. Click Yes to restart the AD CS

If you are using Smartcard Authentication, the prompt will go on the PIN Pad device to insert Smartcard and enter the pin. Then press OK button on the PIN Pad.