Certificate templates
Now we have a working PKI, and we can turn off the standalone root CA. It should only be brought online if the issuing CA certificates are expired or the PKI is compromised.
The CA comes with predefined certificate templates. These can be used to build custom certificate templates according to the organization's requirements and can be published to AD.
CA certificate templates are available under the Certificate Templates MMC. They can be accessed using Run | MMC | File | Add/Remove Snap-in... | Certificate Templates.
- To create a custom template, right-click on a template and click on Duplicate Template:
Figure 13.22: Duplicate certificate template
- This will open up the Properties window, where you can change the settings of the certificate template to match the requirements. Some common settings to change in templates are listed here:
- Template display name (the General tab): The display name of the template...