Certificate Templates

During initial provisioning, the certificate templates in the primary Active Directory forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. (the forest in which Keyfactor Command is installed) will be imported automatically by the Keyfactor Command configuration wizard. Templates for additional forests can be imported in a number of ways:

  • For Microsoft CAs domain-joined to forests in a two-way trust with the primary forest, you can use the Import Templates option at any time.
  • For Microsoft CAs domain-joined to forests in a one-way trust with the primary forest or to a forest having no trust with the primary forest, you can use the Import Templates option after you have configured a CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. record for at least one Microsoft CA in the non-primary forest and enabled the Use Explicit Credentials option with credentials for the non-primary forest.
  • For EJBCA CAs, you can use the Import Templates option after you have configured a CA record for at least one EJBCA CA.
  • Templates that are associated with certificates that have been requested from a Microsoft CA in a forest other than the primary forest will appear in the templates grid as those certificates are synchronized to Keyfactor Command if you configure CA synchronization for the CA even if you don't use the import option.
  • There's an automated process to import templates once every hour, on the hour. Templates are imported for Microsoft CAs in the primary forest, Microsoft CAs in any forests in a two-way trust with the primary forest, and any CAs that can be reached using the credentials configured in the CA record (the Use Explicit Credentials option for Microsoft CAs or the client certificate for EJBCA CAs). The automated templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received. import only runs for CAs for which there is an active CA synchronization job configured. This automated sync is only enabled if the Sync Templates option on the Service tab of the Configuration Wizard is selected during installation (see Service Tab in the Keyfactor Command Server Installation Guide).

You will need to import templates if you add a new template or change the name or key sizeClosed The key size or key length is the number of bits in a key used by a cryptographic algorithm. of a template after it has been imported into Keyfactor Command and don't want to wait for the automated import process or have not configured the automated process (see Importing Certificate Templates).

Certificate templates need to be configured to support PFXClosed A PFX file (personal information exchange format), also known as a PKCS#12 archive, is a single, password-protected certificate archive that contains both the public and matching private key and, optionally, the certificate chain. It is a common format for Windows servers. and CSRClosed A CSR or certificate signing request is a block of encoded text that is submitted to a CA when enrolling for a certificate. When you generate a CSR within Keyfactor Command, the matching private key for it is stored in Keyfactor Command in encrypted format and will be married with the certificate once returned from the CA. enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). (see Configuring Template Options).

Note:  When EJBCA templates are imported, they are named using a naming scheme of:
  • Short Name: <end entity profile name>_<certificate profile name>
  • Display Name: <end entity profile name> (<certificate profile name>)

Only certificate profiles configured as available in a given end entity profile will be imported as templates associated with the given end entity profile name.

Figure 210: Certificate Templates

Tip:  Click the help icon () next to the Certificate Templates page title to open the embedded web copy of the Keyfactor Command Reference Guide to this section.

You can also find the help icon at the top of the page next to the Log Out button. From here you can choose to open either the Keyfactor Command Documentation Suite at the home page or the Keyfactor API Endpoint Utility.