The Certificate Templates snap-in allows you to view and manage critical information about all the certificate templates in a domain.
Important fields in the Certificate Templates snap-in include:
- Template Display Name. This field
describes the purpose of the certificate. When an organization
creates a custom certificate template, it may be useful to use a
naming convention that helps administrators identify the
certification authority (CA) or portion of the organization
associated with the template.
- Minimum Supported CAs. The
configurable options in Windows-based certificate templates differ
based on the operating system version. Therefore, not all
certificate templates are supported by all Windows Server–based
CAs.
- Version. If certificate template
configurations evolve over time, the ability to track version
information becomes important for compatibility and support.
You must be a local administrator to install the Certificate Templates snap-in and a member of Domain Admins to use the Certificate Templates snap-in. For more information, see Implement Role-Based Administration.
To install the Certificate Templates snap-in |
-
Click Start, click Run, and then type mmc.
-
On the File menu, click Add/Remove Snap-in.
-
On the Add and Remove Snap-ins dialog box, double-click the Certificate Templates snap-in to add it to the list. Click OK.
By default, the Certificate Templates snap-in is installed automatically when a CA is installed on a server. The Certificate Templates snap-in can be installed on a different server by using Server Manager to install Active Directory Certificate Services (AD CS) tools.
You must be local administrator to install Remote Server Administration Tools. You must be a member of Domain Admins to access and administer certificate templates for a domain. For more information, see Implement Role-Based Administration.
To administer certificate templates from a remote server |
-
Open Server Manager.
-
Under Features Summary, click Add Features.
-
Expand Remote Server Administration Tools and Role Administration Tools.
-
Select the Active Directory Certificate Services check box, click Next, and then click Install.
-
When the installation process is finished, click Close.
-
Click Start, type mmc, and press ENTER.
-
On the File menu, click Add/Remove Snap-in.
-
Click the Certificate Templates snap-in, click Add, verify that the domain controller hosting the certificate templates you want to manage is selected, and then click OK.
You can use the Certificate Templates snap-in to manage certificate templates in a different domain.
You must be a domain or enterprise administrator for the other domain to complete this procedure. For more information, see Implement Role-Based Administration.
To manage certificate templates in a different domain |
-
Right-click the Certificate Templates snap-in, and click Connect to another writable domain controller.
-
To type the name of a different domain, click Change. To select a different domain controller for the existing domain, click Select a Writable Domain Controller.
-
If you have previously selected an alternate domain controller, you can revert to the original domain controller by clicking Default Writable Domain Controller.