Domain Controller Authentication Certificate
When you install windows 2008 certification authority a new domain controller certificate template named kerberos authentication is available.
Domain controller authentication certificate. Installing a certificate on the domain controller enables the key distribution center kdc to prove its identity to other members of the domain. 1 2 840 113549 1 1 5 sha1rsa algorithm parameters. Make sure that the issuing ca certificate of the user s certificate is installed in the enterprise ntauth store. In the certificate properties dialog box the intended purpose displayed is server authentication.
List domain controller authentication certificates now we can list all certificates we can even pick up the one with domain controller authentication template we just need to read the date when it expires and then mark it with some rag red amber green status based on how close it is to be expired for me i mark it red if it is to expire within 30 days because based on my cert template. Client authentication 1 3 6 1 5 5 7 3 2 server authentication 1 3 6 1 5 5 7 3 1. It replaces the domain controller authentication template. Clients need to trust domain controllers and the best way to do this is to ensure each domain controller has a kerberos authentication certificate.
Certificates issued via this new template contain two specific attributes. Certutil dspublish f. Expand certificates local computer expand personal and then expand certificates. Therefore domain controllers need to request a certificate based on the kerberos authentication certificate template.
By default the active directory certificate authority. Sample certificate x509 certificate. A new certificate should exist in the personal store. However certificates based on the domain controller and domain controller authentication certificate templates do not include the kdc authentication object identifier oid which was later added to the kerberos rfc.
The purpose of the kerberos authentication template is to issue certificates to domain controllers which present the certificates to client computers during user and computer network authentication. Rather than relying on the dns name of the computer applications can verify the following. The domain controller certificate must be installed in the local computer s certificate store. This certificate is issued to the computer s fully qualified host name.
Make sure that a kerberos authentication certificate that has a kdc authentication extended key usage eku has been issued to the domain controllers. This provides clients a root of trust external to the domain namely the enterprise certificate authority.