Administration

Table Of Contents
c Make the following changes on the following tabs:
Tab Action
Compatibility tab
n
For Certificate Authority, select Windows Server 2008 R2.
n
For Certificate Recipient, select Windows 7/Windows Server 2008 R2.
General tab
n
Change the template display name to True SSO.
n
Change the validity period to a period that is as long as a typical working
day; that is, as long as the user is likely to remain logged into the system.
So that the user does not lose access to network resources while logged
on, the validity period must be longer than the Kerberos TGT renewal time
in the users domain.
(The default maximum lifetime of the ticket is 10 hours. To find the default
domain policy, you can go to Computer Configuration > Policies >
Windows Settings > Security Settings > Account Policies > Kerberos
Policy:Maximum lifetime for user ticket.)
n
Change the renewal period to 1 day.
Request Handling tab
n
For Purpose, select Signature and smartcard logon.
n
Select, For automatic renewal of smart cards, …
Cryptography tab
n
For Provider Category, select Key Storage Provider.
n
For Algorithm name, select RSA.
Server tab Select Do not store certificates and requests in the CA database.
Important Make sure to deselect Do not include revocation information in
issued certificates. (This box gets selected when you select the first one, and
you have to deselect (clear) it.)
Issuance Requirements tab
n
Select This number of authorized signatures, and type 1 in the box.
n
For Policy type, select Application Policy and set the policy to
Certificate Request Agent.
n
For, Require the following for reenrollment, select Valid existing
certificate.
Security tab For the security group that you created for the enrollment server computer
accounts, as described in the prerequisites, provide the following permissions:
Read, Enroll
1 Click Add.
2 Specify which computers to allow to enroll for certificates.
3 For these computers select the appropriate check boxes to give the
computers the following permissions: Read, Enroll.
d Click OK in the Properties of New Template dialog box.
e Close the Certificate Templates Console window.
f Right-click Certificate Templates and select New > Certificate Template to Issue.
Note This step is required for all certificate authorities that issue certificates based on this
template.
g In the Enable Certificate Templates window, select the template you just created (for example,
True SSO Template) and click OK.
View Administration
VMware, Inc. 92