Domain Controller Certificate Template
Select the template kerberos authentication and pkcs 10 as format.
Domain controller certificate template. Log in to the domain controller. All of the certificate templates are displayed in the details pane. Email template structures are outwardly engaging for your messages yet making one without any preparation could incline into a quite relentless argument uniquely upon the off unintentional that you have alternative activities.
Add the certificates snap in select computer account. Click the action menu and then click duplicate template. The purpose of the kerberos authentication template is to issue certificates to domain controllers which present the certificates to client computers during user and computer network authentication.
To perform ldaps with domain controllers you must install a certificate into the personal store of the computer account. It replaces the domain controller authentication template. For 3rd party cas until windows 2003 the requirements the certificate must fulfill were outlined in kb 321051.
Certificates issued via this new template contain two specific attributes. When you install windows 2008 certification authority a new domain controller certificate template named kerberos authentication is available. In the details pane click the ras and ias server template.
From the add superseded template dialog select the kerberos authentication certificate template and click ok. From the add superseded template dialog select the domain controller certificate template and click ok. The kerberos authentication certificate template is the most current certificate template designated for domain controllers and should be the one you deploy to all your domain controllers 2008 or later.
If you need more information about the new certificate templates shipped with a windows 2008 ca you can read this article. The lab certificates damen online with domain controller certificate template. Right click on the folder personal certificates and select create custom request.