Administration

Table Of Contents
13 Enter the following commands to restart the service:
sc stop certsvc
sc start certsvc
What to do next
Create a certicate template. See “Create Certicate Templates Used with True SSO,” on page 80.
Create Certificate Templates Used with True SSO
You must create a certicate template that can be used for issuing short-lived certicates, and you must
specify which computers in the domain can request this type of certicate.
You can create more than one certicate template, but you can congure only one template to be used at any
one time.
Prerequisites
n
Verify that you have an enterprise CA to use for creating the template described in this procedure. See
“Set Up an Enterprise Certicate Authority,” on page 78.
n
Verify that you have prepared Active Directory for smart card authentication. For more information, see
the View Installation document.
n
Create a security group in the domain and forest for the enrollment servers, and add the computer
accounts of the enrollment servers to that group.
Procedure
1 On the machine that you are using for the certicate authority, log in to the operating system as an
administrator and go to Administrative Tools >  Authority.
2 Expand the tree in the left pane, right-click  Templates and select Manage.
3 Right-click the Smartcard Logon template and select Duplicate.
4 Make the following changes on the following tabs:
Tab Action
Compatibility tab
n
For  Authority, select Windows Server 2008 R2.
n
For  Recipient, select Windows 7/Windows Server 2008 R2.
General tab
n
Change the template display name to True SSO.
n
Change the validity period to a period that is as long as a typical
working day; that is, as long as he user is likely to remain logged into
the system.
So that the user does not lose access to network resources while logged
on, the validity period must be longer than the Kerberos TGT renewal
time in the users domain.
(The default maximum lifetime of the ticket is 10 hours. To nd the
default domain policy, you can go to Computer  >
Policies > Windows  > Security  > Account Policies >
Kerberos Policy:Maximum lifetime for user ticket.)
n
Change the renewal period to 1 day.
Request Handling tab
n
For Purpose, select Signature and smartcard logon.
n
Select, For automatic renewal of smart cards, …
Cryptography tab
n
For Provider Category, select Key Storage Provider.
n
For Algorithm name, select RSA.
View Administration
80 VMware, Inc.