(Re-)Installing the Microsoft Standard Certificate Templates

There may be cases where it is necessary to install the standard Microsoft certificate templates before installing the first Active Directory integrated certificate authority (Enterprise Certification Authority), or to reinstall the templates, for example because they have been corrupted or otherwise modified.

The following standard certificate templates are defined:

Object nameDisplay name (English)Display Name (German)
AdministratorAdministratorAdministrator
CARoot Certification AuthorityMaster Certification Authority
CAExchangeCA ExchangeCertification Authority exchange
CEPEncryptionCEP EncryptionCEP Encryption
ClientAuthAuthenticated SessionAuthenticated Session
CodeSigningCode SigningCode signature
CrossCACross Certification AuthorityCross-Sector Certification Body
CTLSigningTrust List SigningTrusted List Signature
DirectoryEmailReplication Directory Email ReplicationDirectory Email Replication
DomainControllerDomain controllerDomain controller
DomainControllerAuthenticationDomain Controller AuthenticationDomain Controller Authentication
EFSBasic EFSBasic EFS
EFSRecoveryEFS Recovery AgentEFS Recovery Agent
EnrollmentAgentEnrollment AgentRegistration Agent
EnrollmentAgentOfflineExchange Enrollment Agent (Offline request)Exchange Enrollment Agent (Offline Request)
ExchangeUserExchange UserExchange users
ExchangeUserSignatureExchange User Signature
IPSECIntermediateOfflineIPSec (Offline Request)IPSec (Offline Request)
IPSECIntermediateOnlineIPSecIPSec
KerberosAuthenticationKerberos AuthenticationKerberos authentication
KeyRecoveryAgentKey Recovery AgentKey Recovery Agent
MachineComputerComputer
MachineEnrollmentAgentEnrollment Agent (Computer)Registration Agent (Computer)
OCSPResponseSigningOCSP Response SigningOCSP Response Signature
OfflineRouterRouter (Offline Request)Router (Offline Request)
RASandIASServerRAS and IAS ServerRAS and IAS Servers
SmartcardLogonSmartcard LogonSmartcard login
SmartcardUserSmartcard UserSmart Card Users
SubCASubordinate Certification AuthoritySubordinate Certification Authority
UserUserUser
UserSignatureUser Signature OnlyUser signature only
WebServerWeb ServerWeb server
WorkstationWorkstation AuthenticationWorkstation Authentication

Implementation

Do you know TameMyCerts? TameMyCerts is an add-on for the Microsoft certification authority (Active Directory Certificate Services). It extends the function of the certification authority and enables the Application of regulationsto realize the secure automation of certificate issuance. TameMyCerts is unique in the Microsoft ecosystem, has already proven itself in countless companies around the world and is available under a free license. It can downloaded via GitHub and can be used free of charge. Professional maintenance is also offered.

Reinstalling the certificate templates means deleting them and then creating them again. To delete them, you must have Enterprise Administrator permissions.

The deletion itself is done with the ADSI editor (adsiedit.msc).

You connect to the configuration partition.

The certificate templates are located at Services – Public Key Services…

...below CN=Certificate Templates. Here you can select all or individual certificate templates and delete them by right-clicking.

To reinstall the default certificate templates, there is a corresponding certutil command:

certutil -installdefaulttemplates

Please note that the command must be executed with Enterprise Administrator privileges.

Related links:

External sources

Comments are closed.

en_USEnglish