Issue the Key Recovery Agent Certificate

  1. Open the command prompt and run the certmgr.msc command

image-20251110-091607.png

Figure 47: Certificate Manager window

  1. Right-click Personal node. Select All Tasks then select Request new certificate…

image-20251110-091625.png

Figure 48: Certificate Manager window

  1. Click Next

image-20251110-091639.png

Figure 49: Before You Begin window

  1. Select Certificate Enrollment Policy and click Next

If you are using Smartcard Authentication, the prompt will go on the PIN Pad device to insert Smartcard and enter the pin. Then press OK button on the PIN Pad.

  1. Select the above created Key Recovery Agent check box and click Enroll

image-20251110-091706.png

Figure 50: Certificate Enrollment window

  1. Verify the Enrollment is pending and click Finish