Installation

Table Of Contents
3 Right-click Trusted Root  Authorities and select Import.
4 Follow the prompts in the wizard to import the root certicate (for example, rootCA.cer) and click OK.
5 Close the Group Policy window.
All of the systems in the domain now have a copy of the root certicate in their trusted root store.
What to do next
If an intermediate certication authority (CA) issues your smart card login or domain controller certicates,
add the intermediate certicate to the Intermediate Certication Authorities group policy in Active
Directory. See Add an Intermediate Certicate to Intermediate Certication Authorities,” on page 34.
Add an Intermediate Certificate to Intermediate Certification Authorities
If you use an intermediate certication authority (CA) to issue smart card login or domain controller
certicates, you must add the intermediate certicate to the Intermediate Certication Authorities group
policy in Active Directory.
Procedure
1 On the Active Directory server, navigate to the Group Policy Management plug-in.
AD Version Navigation Path
Windows 2003
a Select Start > All Programs > Administrative Tools > Active Directory
Users and Computers.
b Right-click your domain and click Properties.
c On the Group Policy tab, click Open to open the Group Policy
Management plug-in.
d Right-click Default Domain Policy, and click Edit.
Windows 2008
a Select Start > Administrative Tools > Group Policy Management.
b Expand your domain, right-click Default Domain Policy, and click
Edit.
2 Expand the Computer  section and open the policy for Windows 
 Key.
3 Right-click Intermediate  Authorities and select Import.
4 Follow the prompts in the wizard to import the intermediate certicate (for example,
intermediateCA.cer) and click OK.
5 Close the Group Policy window.
All of the systems in the domain now have a copy of the intermediate certicate in their intermediate
certication authority store.
Add the Root Certificate to the Enterprise NTAuth Store
If you use a CA to issue smart card login or domain controller certicates, you must add the root certicate
to the Enterprise NTAuth store in Active Directory. You do not need to perform this procedure if the
Windows domain controller acts as the root CA.
Procedure
u
On your Active Directory server, use the certutil command to publish the certicate to the Enterprise
NTAuth store.
For example: certutil -dspublish -f path_to_root_CA_cert NTAuthCA
View Installation
34 VMware, Inc.