Create or Identify Templates

The Keyfactor AnyCA Gateway DCOM uses certificate templates stored in Active Directory, configured to match your CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. certificate types, to support enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). for certificates from your CA. When you enroll for a certificate via the AnyCAGateway DCOM, you make a request using the Active Directory templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. and the corresponding type of your CA certificate is requested. Since this template to certificate type mapping is done during the AnyCAGateway DCOM configuration process, you need to create new, or identify existing, templates that will be used for this mapping prior to beginning.

If you have a Microsoft enterprise CA, you can easily create these templates using the Microsoft CA certificate templates MMC snap-in. If you don’t have a Microsoft enterprise CA, you can install the Microsoft Remote Server Administration Tools (RSAT) for Windows and use the Certificate Templates tool within this to manage templates. When you open the Certificate Templates tool for the first time (you’ll need to open it manually in an MMC—it does not appear on the menu), you’ll be offered the option to add the default templates into Active Directory. Doing so will create the necessary starter templates to work from. You can also create the necessary starter templates from the command line using this command:

certutil -installdefaulttemplates

Figure 729: Install Default Certificate Templates in Environments without a Windows CA

The attributes about templates that matter for the purposes of AnyCAGateway DCOM enrollment are: