Administration

Table Of Contents
Create Certificate Templates Used with True SSO
You must create a certificate template that can be used for issuing short-lived certificates, and you must
specify which computers in the domain can request this type of certificate.
You can create more than one certificate template. You can configure only one template per domain but
you can share the template across multiple domains. For example, if you have an Active Directory forest
with three domains and you want to use True SSO for all three domains, you can choose to configure
one, two, or three templates. All domains can share the same template, or you can have different
templates for each domain.
Prerequisites
n
Verify that you have an enterprise CA to use for creating the template described in this procedure.
See Set Up an Enterprise Certificate Authority.
n
Verify that you have prepared Active Directory for smart card authentication. For more information,
see the View Installation document.
n
Create a security group in the domain and forest for the enrollment servers, and add the computer
accounts of the enrollment servers to that group.
Procedure
1 To configure True SSO, on the machine that you are using for the certificate authority, log in to the
operating system as an administrator and go to Administrative Tools > Certification Authority.
a Expand the tree in the left pane, right-click Certificate Templates and select Manage.
b Right-click the Smartcard Logon template and select Duplicate.
View Administration
VMware, Inc. 90