Certificate Templates

During initial provisioning, certificate templates are imported automatically if Keyfactor Command is installed on Windows and the primary environment includes Microsoft CAs in the Active Directory forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. where Keyfactor Command is installed. Templates from other environments or CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. types can be imported in several ways:

Templates associated with certificates issued by any configured CA will appear automatically in the templates grid as those certificates are synchronized to Keyfactor Command. Templates may also appear independently as part of the hourly automated templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. import process, even if no certificates have yet been synchronized.

Note:  The hourly automated template import only runs for CAs for which there is an active CA synchronization job configured.

Templates will need to be re-imported if you add a new template or change the name or key sizeClosed The key size or key length is the number of bits in a key used by a cryptographic algorithm. of a template after it has been imported into Keyfactor Command and don't want to wait for the automated import process (see Importing Certificate Templates).

To support PFXClosed A PFX file (personal information exchange format), also known as a PKCS#12 archive, is a single, password-protected certificate archive that contains both the public and matching private key and, optionally, the certificate chain. It is a common format for Windows servers. and CSRClosed A CSR or certificate signing request is a block of encoded text that is submitted to a CA when enrolling for a certificate. When you generate a CSR within Keyfactor Command, the matching private key for it is stored in Keyfactor Command in encrypted format and will be married with the certificate once returned from the CA. enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA)., certificate templates need to be configured with enrollment patterns (see Adding or Modifying an Enrollment Pattern) and the certificate authorities that will issue the certificates need to be enabled for enrollment (see HTTPS CAs - Advanced Tab or DCOM CAs - Advanced Tab).

Note:  When EJBCA templates are imported, their names follow this convention:
  • Short Name: <end entity profile name>_<certificate profile name>
  • Display Name: <end entity profile name> (<certificate profile name>)

If the end entity profile name and certificate profile name are the same, only the end entity profile name is used.

For example, if both names are Development Web Server, the Short Name and Display Name will both be Development Web Server.

Only certificate profiles configured as available in a given end entity profile will be imported as templates associated with the given end entity profile name.

Tip:  Click the help icon () next to the Certificate Templates page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).