Configure the Server Certificate Template (2024)

  • Article

Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016

You can use this procedure to configure the certificate template that Active Directory® Certificate Services (AD CS) uses as the basis for server certificates that are enrolled to servers on your network.

While configuring this template, you can specify the servers by Active Directory group that should automatically receive a server certificate from AD CS.

The procedure below includes instructions for configuring the template to issue certificates to all of the following server types:

  • Servers that are running the Remote Access service, including RAS Gateway servers, that are members of the RAS and IAS Servers group.
  • Servers that are running the Network Policy Server (NPS) service that are members of the RAS and IAS Servers group.

Membership in both the Enterprise Admins and the root domain's Domain Admins group is the minimum required to complete this procedure.

To configure the certificate template

  1. On CA1, in Server Manager, click Tools, and then click Certification Authority. The Certification Authority Microsoft Management Console (MMC) opens.

  2. In the MMC, double-click the CA name, right-click Certificate Templates, and then click Manage.

  3. The Certificate Templates console opens. All of the certificate templates are displayed in the details pane.

  4. In the details pane, click the RAS and IAS Server template.

  5. Click the Action menu, and then click Duplicate Template. The template Properties dialog box opens.

  6. Click the Security tab.

  7. On the Security tab, in Group or user names, click RAS and IAS servers.

  8. In Permissions for RAS and IAS servers, under Allow, ensure that Enroll is selected, and then select the Autoenroll check box. Click OK, and close the Certificate Templates MMC.

  9. In the Certification Authority MMC, click Certificate Templates. On the Action menu, point to New, and then click Certificate Template to Issue. The Enable Certificate Templates dialog box opens.

  10. In Enable Certificate Templates, click the name of the certificate template that you just configured, and then click OK. For example, if you did not change the default certificate template name, click Copy of RAS and IAS Server, and then click OK.

Feedback

Coming soon: Throughout 2024 we will be phasing out GitHub Issues as the feedback mechanism for content and replacing it with a new feedback system. For more information see: https://aka.ms/ContentUserFeedback.

Submit and view feedback for

Configure the Server Certificate Template (2024)

FAQs

How to configure certificate template? ›

To configure a CA to issue certificates based on a certificate template, perform the following steps:
  1. Open the Certification Authority snap-in, and double-click the name of the CA.
  2. Right-click Certificate Templates, click New, and then click Certificate Template to Issue.
  3. Select the certificate template, and click OK.
Mar 8, 2024

What is the purpose of the certificate template? ›

It is the Certificate Template that specifies the data that must be included in a certificate for it to function as well as to ensure that all of the needed data are provided to ensure the certificate's validity.

How to create a web server certificate template? ›

How to create a web server SSL certificate manually
  1. Creating an INF file to set the certificate properties. Use Notepad to modify the following sample INF file according to your needs. ...
  2. Compiling the INF file into a REQ file. ...
  3. Submitting the REQ file to the CA. ...
  4. Installing the certificate at the IIS or ISA computer.
Jan 24, 2020

How do I create a certificate on my server? ›

Detailed procedure
  1. Install OpenSSL. ...
  2. Creating the CA. ...
  3. generate the key for the server certificate. ...
  4. Certificate Signing Request erzeugen. ...
  5. Customise the OpenSSL configuration. ...
  6. Sign the Server Certificate. ...
  7. Install the certificate.

How do I edit a certificate template? ›

Editing a Certificate Template
  1. Search for the certificate template that you want to edit. ...
  2. From the search results, click the name of the desired certificate template. ...
  3. Make the desired edits.
  4. Click Save or click Save and Add Another if you wish to add an additional new certificate template.

How do certificate templates work? ›

Certificate templates also give instructions to the client on how to create and submit a valid certificate request. Only an enterprise CA can issue certificates based on a certificate template. The templates are stored in Active Directory Domain Services (AD DS) for use by every CA in the forest.

Where are certificate templates? ›

Certificate templates can be accessed from the Workplace launcher or via Site administration > Certificates > Manage certificate templates. The permission Manage certificates (tool/certificate:manage) has to be granted to access this feature. You see a list of certificate templates.

How do I access certificate templates? ›

Click File, and then click Add/Remove Snap-in. In the available snap-ins list, click Certificate Templates, and then click Add. Certificate Templates is now located under Console Root in the MMC. Double-click it to view all the available certificate templates.

How to generate server certificate and client certificate? ›

Server certificate
  1. Generate the Server Certificate Private Key using the following command line: openssl ecparam -name prime256v1 -genkey -noout -out server. ...
  2. Generate the server Certificate Signing Request (CSR) using the following command line: openssl req -new -sha256 -key server.

What is a web server certificate? ›

The server certificate, a digital document that verifies the identification of a website or server, is fundamental to Internet communication security.

What is web server template? ›

A web server template is used to define the configuration settings for a new web server.

What certificates does a server need? ›

A Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate provides encryption capabilities for ensuring secure data transmission between your customers' web browsers and your website server.

How do certificates work on servers? ›

If the browser trusts the certificate, it creates, encrypts, and sends back a symmetric session key using the server's public key. Server decrypts the symmetric session key using its private key and sends back an acknowledgement encrypted with the session key to start the encrypted session.

How do I enable a certificate template in CA? ›

Enabling a new certificate template on the CA
  1. Log on to the CA server with administrative credentials.
  2. Open the Server Manager and select Roles > Active Directory > Certificate Services > Certificate Templates.
  3. Right-click Certificate Templates, and then select New > Certificate Template to Issue.

How to import certificate template? ›

Add the Certificate Templates Snap-In
  1. Select Start > Administrative Tools > Server Manager, right click Server Manager and choose Add Features.
  2. Open Remote Server Administration Tools > Role Administration Tools > Active Directory Certificate Services Tools and select Certification Authority Tools.

Top Articles
Latest Posts
Article information

Author: Rueben Jacobs

Last Updated:

Views: 5925

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Rueben Jacobs

Birthday: 1999-03-14

Address: 951 Caterina Walk, Schambergerside, CA 67667-0896

Phone: +6881806848632

Job: Internal Education Planner

Hobby: Candle making, Cabaret, Poi, Gambling, Rock climbing, Wood carving, Computer programming

Introduction: My name is Rueben Jacobs, I am a cooperative, beautiful, kind, comfortable, glamorous, open, magnificent person who loves writing and wants to share my knowledge and understanding with you.