SCEP Certificate Template Configuration
A custom certificate template must be created to support SCEP-based certificate enrollment with required security and key configurations.
About this task
Procedure
-
Open Certificate Templates Console. Run
certtmpl.msc -
Duplicate Existing Template
- Locate
Computer - Right-click Duplicate Template
- Locate
-
Configure General Settings: Template Display Name (Sample):
BigFix SCEP Device Template -
Configure Cryptography Settings
Go to Cryptography tab:
- Minimum key size:
4096
- Minimum key size:
- Configure Private Key Settings: Go to Request Handling tab: Allow/Disallow Private Key export by checking/unchecking Allow private key to be exported check box.
-
Configure Subject Name:
Go to Subject Name tab:
- Select:
Supply in the request
- (or) Build from Active Directory information
- Select:
-
Configure Extensions (Optional based on requirement):
Ensure the certificate template includes the required Application Policies
- Go to Extensions tab
- Select: Application Policies
- Click Edit
- Ensure the following is present: Client Authentication
-
Configure Security Permissions:
Proper permissions are required for NDES to enroll certificates using this template.
- Go to Security tab
- Add the following account: NDES Service Account
- Grant the following permissions:
- Read
- Enroll