Configuring Templates
Creating and Configuring Certificate Templates¶
Certificate templates in Active Directory Certificate Services (AD CS) define the rules and properties for certificate issuance. They specify key usage, extended key usage, validity periods, and other attributes that determine how certificates are issued and used. Proper configuration ensures secure and efficient certificate management for scenarios like code signing, email encryption, and server authentication.
Creating a Certificate Template¶
To create a certificate template, use the Certification Authority (CA) management console or PowerShell. Below is a step-by-step example using PowerShell:
Example: Create a Code Signing Certificate Template¶
# Create a new certificate template
New-CATemplate -Name "CodeSigningTemplate" -Subject "CN=Code Signing Certificate" `
-KeyUsage DigitalSignature, KeyEncipherment -ExtendedKeyUsage "Code Signing" `
-ValidityPeriod Years -ValidityPeriodUnits 2 -EnrollmentFlags "AllowEnrollment"
Key Parameters:
- -Name: Specifies the template name.
- -Subject: Defines the subject name format (e.g., CN=...).
- -KeyUsage: Specifies allowed key usages (e.g., DigitalSignature, KeyEncipherment).
- -ExtendedKeyUsage: Lists extended key usages (e.g., Code Signing, Server Authentication).
- -ValidityPeriod/-ValidityPeriodUnits: Sets the certificate's validity duration.
- -EnrollmentFlags: Controls enrollment permissions (e.g., AllowEnrollment).
Configuring Template Properties¶
After creation, templates must be configured for specific use cases. Key settings include:
1. Key Usage and Extended Key Usage¶
- Key Usage: Determines how the private key is used (e.g., signing, encryption).
- Extended Key Usage: Specifies additional purposes (e.g., server authentication, client authentication).
Example: Configure a template for email encryption:
Set-CATemplate -Name "EmailEncryptionTemplate" -ExtendedKeyUsage "Email Protection" `
-KeyUsage KeyEncipherment, DataEncipherment
2. Validity Periods¶
- Set
ValidityPeriodtoYearsorMonthsand defineValidityPeriodUnits.
3. Revocation Settings¶
- Enable revocation checks via CRL or OCSP:
4. Permissions¶
- Use
Set-CATemplateto assign permissions (e.g., allowing users to enroll certificates):
Deploying the Template¶
Once configured, publish the template to make it available for certificate requests:
1. Publish via PowerShell¶
2. Verify Publication¶
Check the CA management console under Certificate Templates > Active Templates to confirm the template is published.
Use Cases and Examples¶
| Use Case | Template Configuration |
|---|---|
| Web Server SSL | Extended Key Usage: Server Authentication, Validity: 1 Year |
| Email Encryption | Extended Key Usage: Email Protection, Key Usage: KeyEncipherment, Validity: 2 Years |
| Code Signing | Extended Key Usage: Code Signing, Key Usage: DigitalSignature, Validity: 3 Years |
Key takeaways¶
- Use PowerShell (
New-CATemplate,Set-CATemplate) to create and configure templates efficiently. - Tailor key usage, extended key usage, and validity periods to match specific use cases.
- Publish templates to make them available for enrollment and ensure proper revocation settings are enabled.
- Regularly audit and update templates to align with organizational security policies.