Administration

Table Of Contents
Add the Root Certificate to the Enterprise NTAuth Store
If you use a CA to issue smart card login or domain controller certicates, you must add the root certicate
to the Enterprise NTAuth store in Active Directory. You do not need to perform this procedure if the
Windows domain controller acts as the root CA.
Procedure
u
On your Active Directory server, use the certutil command to publish the certicate to the Enterprise
NTAuth store.
For example: certutil -dspublish -f path_to_root_CA_cert NTAuthCA
The CA is now trusted to issue certicates of this type.
Add the Root Certificate to Trusted Root Certification Authorities
If you use a certication authority (CA) to issue smart card login or domain controller certicates, you must
add the root certicate to the Trusted Root Certication Authorities group policy in Active Directory. You do
not need to perform this procedure if the Windows domain controller acts as the root CA.
Procedure
1 On the Active Directory server, navigate to the Group Policy Management plug-in.
AD Version Navigation Path
Windows 2003
a Select Start > All Programs > Administrative Tools > Active Directory
Users and Computers.
b Right-click your domain and click Properties.
c On the Group Policy tab, click Open to open the Group Policy
Management plug-in.
d Right-click Default Domain Policy, and click Edit.
Windows 2008
a Select Start > Administrative Tools > Group Policy Management.
b Expand your domain, right-click Default Domain Policy, and click
Edit.
2 Expand the Computer  section and open Windows  
Key.
3 Right-click Trusted Root  Authorities and select Import.
4 Follow the prompts in the wizard to import the root certicate (for example, rootCA.cer) and click OK.
5 Close the Group Policy window.
All of the systems in the domain now have a copy of the root certicate in their trusted root store.
What to do next
If an intermediate certication authority (CA) issues your smart card login or domain controller certicates,
add the intermediate certicate to the Intermediate Certication Authorities group policy in Active
Directory. See Add an Intermediate Certicate to Intermediate Certication Authorities,” on page 52.
Chapter 3 Setting Up Smart Card Authentication
VMware, Inc. 51