The first step in certificate generation and replacement is setting up a Microsoft Certificate Authority template on the Active Directory (AD) servers for the region. After you have created the new template, you add it to the certificate templates of the Microsoft CA.

Prerequisites

  • Verify that you installed Microsoft Server 2012 R2 with Active Directory Domain Services enabled.

  • Verify that The Certificate Authority Service role and the Certificate Authority Web Enrolment role is installed and configured on the Active Directory Server.

  • Verify that dc51lax.lax01.rainpole.local has been set up to be the intermediate CA of the root CA dc01rpl.rainpole.local.

  • Use a hashing algorithm of SHA-2 or higher on the certificate authority.

Procedure

  1. Log in to the following AD server by using a Remote Desktop Protocol (RDP) client.

    Setting

    Value

    FQDN

    • If you use the intermediate CA, connect to dc01lax.lax01.rainpole.local.

    • If you use only the root CA, connect dc01rpl.rainpole.local.

    User name

    Active Directory administrator

    Password

    ad_admin_password

  2. Click Start > Run, enter certtmpl.msc, and click OK
  3. In the Certificate Template Console, under Template Display Name, search the list to see if you can find a template with the name VMware exists.
  4. If a template with the name VMware already exists, go to Step 11.
  5. In the Certificate Template Console, under Template Display Name, right-click Web Server and click Duplicate Template.
  6. In the Duplicate Template window, leave Windows Server 2003 Enterprise selected for backward compatibility and click OK
  7. In the Properties of New Template dialog box, click the General tab.
  8. In the Template display name text box, enter VMware as the name of the new template.
  9. Click the Extensions tab and specify extensions information:
    1. Select Application Policies and click Edit.
    2. Select Server Authentication, click Remove, and click OK.
    3. Select Key Usage and click Edit.
    4. Click the Signature is proof of origin (nonrepudiation) check box.
    5. Leave the default for all other options.
    6. Click OK.
  10. Click the Subject Name tab, ensure that the Supply in the request option is selected, and click OK to save the template.
  11. To add the new template to your CA, click Start > Run, enter certsrv.msc, and click OK.
  12. In the Certification Authority window, expand the left pane if it is collapsed. 
  13. Right-click Certificate Templates and select New > Certificate Template to Issue.
  14. In the Enable Certificate Templates dialog box, select the VMware certificate that you just created in the Name column and click OK.