Certificate Templates

During initial provisioning, certificate templates are imported automatically when Keyfactor Command is installed on Windows and the primary environment includes Microsoft CAs in the Active Directory forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. where Keyfactor Command is installed.

Templates from other environments or CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. types can be imported manually using the Import Templates option, as described below.

Tip:  Where to find this in the Management Portal:
Locations → Certificate Templates

Supported Import Sources

Certificate templates can be imported from the following certificate authorityClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. types.

Automated Template Import

Templates associated with certificates issued by configured CAs appear automatically in the templates grid as certificates are synchronized to Keyfactor Command. Templates may also appear independently through the hourly automated templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. import process, even if no certificates have yet been synchronized.

The hourly automated template import runs only for CAs that have an active CA synchronization job configured.

Re-importing Templates

Templates must be re-imported if you add a new template or change the name or key sizeClosed The key size or key length is the number of bits in a key used by a cryptographic algorithm. of an existing template and do not want to wait for the automated import process. For more information, see Import Templates.

Template Requirements for Enrollment

To support PFXClosed A PFX file (personal information exchange format), also known as a PKCS #12 archive, is a single, password-protected certificate archive that contains both the public and matching private key and, optionally, the certificate chain. It is a common format for Windows servers. and CSRClosed A CSR or certificate signing request is a block of encoded text that is submitted to a CA when enrolling for a certificate. When you generate a CSR within Keyfactor Command, the matching private key for it is stored in Keyfactor Command in encrypted format and will be married with the certificate once returned from the CA. enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA)., certificate templates need to be configured with enrollment patterns (see Add or Modify an Enrollment Pattern) and the certificate authorities that will issue the certificates need to be enabled for enrollment (see HTTPS CAs Advanced Tab or DCOM CAs Advanced Tab).

Certificate Template Management

In Keyfactor Command, certificate templates are typically imported from their source certificate authority rather than created directly within the platform. However, for certain CA types—such as EJBCA instances managed directly or through a CA connector—templates can also be created and managed from within Keyfactor Command.

Depending on the CA type and environment, templates can be imported, viewed, modified, and, where supported, created to support enrollment and certificate management workflows.

From the Certificate Templates page, you can import templates, configure Keyfactor Command-specific template settings, view template details, and—where supported—create or manage templates directly on the CA.

The following sections describe the available certificate template actions.