(Re-)Installing the Microsoft Standard Certificate Templates

There may be cases where it is necessary to install the standard Microsoft certificate templates before installing the first Active Directory integrated certificate authority (Enterprise Certification Authority), or to reinstall the templates, for example because they have been corrupted or otherwise modified.

The following standard certificate templates are defined:

Object nameDisplay name (English)
AdministratorAdministrator
CARoot Certification Authority
CAExchangeCA Exchange
CEPEncryptionCEP Encryption
ClientAuthAuthenticated Session
CodeSigningCode Signing
CrossCACross Certification Authority
CTLSigningTrust List Signing
DirectoryEmailReplication Directory Email Replication
DomainControllerDomain controller
DomainControllerAuthenticationDomain Controller Authentication
EFSBasic EFS
EFSRecoveryEFS Recovery Agent
EnrollmentAgentEnrollment Agent
EnrollmentAgentOfflineExchange Enrollment Agent (Offline request)
ExchangeUserExchange User
ExchangeUserSignatureExchange User Signature
IPSECIntermediateOfflineIPSec (Offline Request)
IPSECIntermediateOnlineIPSec
KerberosAuthenticationKerberos Authentication
KeyRecoveryAgentKey Recovery Agent
MachineComputer
MachineEnrollmentAgentEnrollment Agent (Computer)
OCSPResponseSigningOCSP Response Signing
OfflineRouterRouter (Offline Request)
RASandIASServerRAS and IAS Server
SmartcardLogonSmartcard Logon
SmartcardUserSmartcard User
SubCASubordinate Certification Authority
UserUser
UserSignatureUser Signature Onl
WebServerWeb Server
WorkstationWorkstation Authentication

Reinstalling the certificate templates means deleting them and then creating them again. To delete them, you must have Enterprise Administrator permissions.

The deletion itself is done with the ADSI editor (adsiedit.msc).

You connect to the configuration partition.

The certificate templates are located at ServicesPublic Key Services

...below CN=Certificate Templates. Here you can select all or individual certificate templates and delete them by right-clicking.

To reinstall the default certificate templates, there is a corresponding certutil command:

certutil -installdefaulttemplates

Please note that the command must be executed with Enterprise Administrator privileges.

Related links:

External sources

en_USEnglish