Configure the CA to Create a Certificate Template and Issuing Properties for a PGP User Certificate

  1. Open the Microsoft Management Console by typing in mmc in the Run dialog.

  2. In the Microsoft Management Console select File Add/Remove Snap-in…

  3. Select Certificate Templates in the list with available snap-ins, click Add, and then click OK.

image-3285319703-1.jpg

Microsoft Management Console - certificate templates

  1. Under Console Root, expand the Certificate Templates snap-in. In the middle section, all certificate templates available to the CA are listed.

  2. Scroll down the list until the User template, right-click and click Duplicate Template.

  3. In the pop-up dialog that appears, select the General tab.

  4. Enter the Template display name, e.g. PGP User, and ensure that Publish certificate in Active Directory is selected.

image-3285319703-2.jpg

Microsoft Management Console - properties of new template

  1. Select the Compatibility tab and choose the following compatibility settings from the corresponding pulldown lists:

    1. Certification Authority: Windows Server 2012 R2.

    2. Certification recipient: Windows 7 / Server 2008 R2.

image-3285319703-3.jpg

Microsoft Management Console - properties of new template

  1. Select the Cryptography tab and ensure that Provider Category Key Storage Provider is selected.

Choose Request must use one of the following providers and select Utimaco CryptoServer Key Storage Provider. Finally select the requested hash, e.g. SHA256.

image-3285319703-4.jpg

Microsoft Management Console - properties of new template

  1. Select the Subject Name tab and uncheck the Include e-mail name in subject name and E-mail name check boxes.

  2. Select the Security tab and:

    1. Add and provide the Read and Enroll permissions for the following:

      1. Authenticated Users.

      2. Administrator b For Domain Admins and Enterprise Admins, make sure that Read, Write, and Enroll check boxes are ticked.

  3. Click Apply and then OK.

  4. Close the Microsoft Management Console.