Certificate Template Operations

In Keyfactor Command, certificate templates are typically imported from their source CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. rather than created directly within the product. Depending on your CA type and environment, you can manage templates in several ways from the Certificate Templates page—ranging from importing or editing existing templates to creating new ones on supported CAs and viewing templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. details.

Tip:  Where to find this in the Management Portal:
Locations → Certificate Templates

Supported actions on the certificate template page include:

  • Import Templates

    The certificate templates in the primary Active Directory forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. (the forest in which Keyfactor Command is installed) will be imported automatically by the Keyfactor Command configuration wizard during the Keyfactor Command installation if Keyfactor Command is installed on a domain-joined server. The template import option is used for templates from other sources, new templates created or edited after the Keyfactor Command installation, or template import for non-domain-joined Keyfactor Command servers.

  • Edit Template Options

    Although templates are imported from their source, there are Keyfactor Command-specific settings that can be configured on the templates to allow them to be used within the product.

  • Create/Edit/View/Copy Template on the CA

    View the template configurations as defined on the CA and, where supported, create a new template that will synchronize to the CA. New templates can be created either manually or by copying an existing template.

    Note:  This feature is supported only for EJBCA version 9.1 or later. This capability is not available when connecting to EJBCA through a gateway, through a CA connector, or to EJBCA environments that operate only RA services (without direct CA access).
  • View Certificates for a Template

    The view certificates option takes you to the certificate search interface with the query field populated by the selected template.

  • View Extensions

    View the custom certificate extensions configured on the CA, to aid in configuring new templates using the Create Template option.

    Note:  This feature is supported only for EJBCA version 9.1 or later. This capability is not available when connecting to EJBCA through a gateway, through a CA connector, or to EJBCA environments that operate only RA services (without direct CA access).