Domain Controller Authentication Certificate Template
To perform ldaps with domain controllers you must install a certificate into the personal store of the computer account.
Domain controller authentication certificate template. It replaces the domain controller authentication template. The purpose of the kerberos authentication template is to issue certificates to domain controllers which present the certificates to client computers during user and computer network authentication. In the certificate template console right click the domain controller authentication kerberos or the name of the certificate template you created in the previous section template in the details pane and click properties. When you install windows 2008 certification authority a new domain controller certificate template named kerberos authentication is available.
Windows domain controller certificate template for ldaps strong kdc etc. Log in to the domain controller. Right click certificate templates and click manage. In the certificate templates console right click the domain controller authentication kerberos or the name of the certificate template you created in the previous section template in the details pane and click properties.
If you need more information about the new certificate templates shipped with a windows 2008 ca you can read this article. Domain controller authentication then kerberos authentication supersede it. Click the superseded templates tab. Click the superseded templates tab.
Click the superseded templates tab. Certificates issued via this new template contain two specific attributes. Select the template kerberos authentication and pkcs 10 as format. The enable certificate templates dialog box opens.
If your ca is running enterprise edition then consider switching to the newer kerberos template while a lot of the functions that it satisfies will be handled by a computer certificate some of the. On the action menu point to new and then click certificate template to issue. Right click certificate templates and click manage. You ll definitely want to have your dcs have a domain controller style certificate domain controller is the old one.
In the certification authority mmc click certificate templates. Right click certificate templates and click manage. In the certificate template console right click the domain controller authentication kerberos or the name of the certificate template you created in the previous section template in the details pane and click properties. Right click on the folder personal certificates and select create custom request.
To request domain controller certificates from nexus. For each domain controller. Add the certificates snap in select computer account. If you are using windows enterprise cas it is.