Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 19, 2004

Access Denied: Using Windows Server 2003's Certificate Templates

RSS
Subscribe to Windows IT Pro | See More Microsoft Management Console (MMC) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

I'm playing around with Windows Server 2003's Certificate Services in preparation for upgrading our Windows 2000 Certification Authorities (CAs). I've noticed many new certificate templates in the Windows 2003 Microsoft Management Console (MMC) Certificate Templates snap-in, but I can't enable them. When I open the MMC Certification Authority snap-in, right-click the Certificate Templates folder, then click New, Certificate Template to Issue, I see only a subset of the templates that are available in the Certificate Templates snap-in. Where are the rest of the templates, and why can't I issue them from this CA?

Evidently you're testing Windows 2003, Standard Edition or Windows 2003, Web Edition. Microsoft significantly enhanced certificate templates in Windows 2003 but in effect charges a premium to use that functionality by enabling it only for Windows 2003, Enterprise Edition and Windows 2003 Datacenter Edition.

Windows 2003 offers several new certificate templates that give you more versatility and finer control over the properties that constitute a certificate. Moreover, you can duplicate the default certificate templates and customize them to your needs. For example, you can control the intended purposes (e.g., Server Authentication, Client Authentication, encryption, digital signature) for certificates issued by a given template. You can also control the issuance policy for each template to allow some templates to be issued automatically without CA administrator approval whereas other templates require administrator authorization.

Windows 2003 also includes a new feature called Autoenrollment. Traditionally, when you wanted to deploy a certain type of certificate to a set of users or computers, you had to configure one or more Group Policy Objects (GPOs) in Active Directory (AD) with an Automatic Certificate Request setting (under Computer Configuration\Windows Settings\Security Settings\Public Key Policies in any GPO) that directed the users or computers to request a certificate according to the associated template. With Autoenrollment, you can simply add the desired template to your CA's Certificate Templates folder. After you do so, the ACL will automatically request the new certificate for all computers and users who have Enroll permission on the templates--you don't need to configure Group Policy.

To control which computers or users will request the certificate template, simply open the Certificate Templates snap-in, then open the desired template's Properties page. Click the Security tab and grant Enroll permission to the user accounts or computers that you want to enroll. If you check the Certificate Templates snap-in's Minimum Supported CAs column, you'll notice that certificates that support customization and Autoenrollment can be issued only by Windows 2003 Enterprise or Windows 2003 Datacenter CAs. You can issue all other certificates from Win2K and later servers. You'll also notice that Autoenrollment works only for new clients, such as Windows 2003 and Windows XP clients.

End of Article



Reader Comments
You did not answer the question. I am on a Windows Server 2003 enterprise edition and I have the exact same problem. I see the duplicate template in the "certificate template" snap-in BUT when I attempt to enable them I get the following: I open the MMC Certification Authority snap-in, right-click the Certificate Templates folder, then click New, Certificate Template to Issue, I do not SEE the one that I just created to be able to enable it.

Anonymous User June 08, 2005 (Article Rating: )


Weak executive summary article. These articles are supposed to be for techies, not executives.

mark_a_hatfield July 29, 2005 (Article Rating: )


this article is more focused on information than solution

cryptol July 15, 2008 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Kon-Boot Lets You Bypass Logon for Windows and Linux

Kon-Boot looks like a very interesting tool since it can get you into a system without having to logon first. ...

Google to Take On Windows with New OS

It's official: Google will compete head-to-head with Microsoft's dominant Windows OS with a new system called Google Chrome OS. Based on the Google Chrome browser and not its previous OS effort, the smart phone-based Android system, Google Chrome OS will ...

Q. How can I continually check a performance counter from Windows PowerShell?

...


Security Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Related Events WinConnections and Microsoft® Exchange Connections

Security Summit

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Test Drive IT Solutions and Get Free Music Downloads
Solve your toughest IT problems with these free downloads and receive 5 free music downloads!


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing