(Re-)Installing the Microsoft Standard Certificate Templates

There may be cases where it is necessary to install the standard Microsoft certificate templates before installing the first Active Directory integrated certificate authority (Enterprise Certification Authority), or to reinstall the templates, for example because they have been corrupted or otherwise modified.

The following standard certificate templates are defined:

Object nameDisplay name (English)Anzeigename (Deutsch)
AdministratorAdministratorAdministrator
CARoot Certification AuthorityMaster Certification Authority
CAExchangeCA ExchangeCertification Authority exchange
CEPEncryptionCEP EncryptionCEP-Verschlüsselung
ClientAuthAuthenticated SessionAuthentifizierte Sitzung
CodeSigningCode SigningCode signature
CrossCACross Certification AuthorityÜbergreifende Zertifizierungsstelle
CTLSigningTrust List SigningVertrauenslistensignatur
DirectoryEmailReplication Directory Email ReplicationVerzeichnis-E-Mail-Replikation
DomainControllerDomain controllerDomain controller
DomainControllerAuthenticationDomain Controller AuthenticationDomänencontrollerauthentifizierung
EFSBasic EFSBasis-EFS
EFSRecoveryEFS Recovery AgentEFS-Wiederherstellungsagent
EnrollmentAgentEnrollment AgentRegistrierungs-Agent
EnrollmentAgentOfflineExchange Enrollment Agent (Offline request)Exchange Enrollment Agent (Offlineanforderung)
ExchangeUserExchange UserExchange-Benutzer
ExchangeUserSignatureExchange User Signature
IPSECIntermediateOfflineIPSec (Offline Request)IPSec (Offlineanforderung)
IPSECIntermediateOnlineIPSecIPSec
KerberosAuthenticationKerberos AuthenticationKerberos authentication
KeyRecoveryAgentKey Recovery AgentSchlüsselwiederherstellungs-Agent
MachineComputerComputer
MachineEnrollmentAgentEnrollment Agent (Computer)Registrierungs-Agent (Computer)
OCSPResponseSigningOCSP Response SigningOCSP-Antwortsignatur
OfflineRouterRouter (Offline Request)Router (Offlineanforderung)
RASandIASServerRAS and IAS ServerRAS- und IAS-Server
SmartcardLogonSmartcard LogonSmartcard login
SmartcardUserSmartcard UserSmartcard-Benutzer
SubCASubordinate Certification AuthorityUntergeordnete Zertifizierungsstelle
UserUserUser
UserSignatureUser Signature OnlyNur Benutzersignatur
WebServerWeb ServerWeb server
WorkstationWorkstation AuthenticationArbeitsstationsauthentifizierung

Implementation

Do you know TameMyCerts? TameMyCerts is an add-on for the Microsoft certification authority (Active Directory Certificate Services). It extends the function of the certification authority and enables the Application of regulationsto realize the secure automation of certificate issuance. TameMyCerts is unique in the Microsoft ecosystem, has already proven itself in countless companies around the world and is available under a free license. It can downloaded via GitHub and can be used free of charge. Professional maintenance is also offered.

Reinstalling the certificate templates means deleting them and then creating them again. To delete them, you must have Enterprise Administrator permissions.

The deletion itself is done with the ADSI editor (adsiedit.msc).

You connect to the configuration partition.

The certificate templates are located at ServicesPublic Key Services

...below CN=Certificate Templates. Here you can select all or individual certificate templates and delete them by right-clicking.

To reinstall the default certificate templates, there is a corresponding certutil command:

certutil -installdefaulttemplates

Please note that the command must be executed with Enterprise Administrator privileges.

Related links:

External sources

Comments are closed.

en_USEnglish