Add a Key Recovery Agent (KRA) Template to CA

  1. Open the command prompt and run the certtmpl.msc command. Right-click on the Key Recovery Agent template, then select Duplicate Template.

image-20250804-145947.png


"Certificate Template" Window

  1. The Properties window opens, showing the Compatibility tab. Select appropriate Windows version under Certificate Authority and the Certificate Recipient drop-down box.

image-20250804-150028.png


"Compatibility Tab" Window

  1. Select the General tab. In Template display name, type a name for the template.

  2. Select the Request Handling tab, and in Purpose select Encryption, and Allow private key to be exported is selected.

image-20250804-150125.png


"Request Handling" Window

If you are using smartcard authentication, the prompt will appear on the PIN Pad device to insert the smartcard and enter the PIN. Then, press the OK button on the PIN Pad.

  1. Select the Issuance Requirement tab and deselect CA Certificate manager approval.

  2. Select the Cryptography tab, and in the Provider category, select Key storage provider.

  3. In Algorithm Name, select the algorithm from the list.

  4. Select Requests must use one of the following providers, and in Providers select Utimaco CryptoServer Key Storage Provider only.

If the CA is on Windows Server Core and you are managing it remotely using certtmpl.msc on a different PC, you need to install the Utimaco CryptoServer Key Storage Provider on the PC that is running certtmpl.msc. Otherwise, the Utimaco CryptoServer provider will not appear.

  1. In Request Hash, select a hash type.

  2. From the Security tab, verify if Domain Admins and Enterprise Admins have Enroll Permissions.

  3. Select Apply and click OK to save the template settings and close the Certificate Template console.

  4. Open the command prompt and run the certsrv.msc command.

  5. Right-click the Certificate Templates node. Select New, then select Certificate Template to Issue.

  6. Select the template created in the above steps and click OK.