7.0

Table Of Contents
Procedure
1 On the machine that you are using for the certificate authority, log in to the operating system as an
administrator and go to Administrative Tools > Certification Authority.
2 Expand the tree in the left pane, right-click Certificate Templates and select Manage.
3 Right-click the Smartcard Logon template and select Duplicate.
4 Make the following changes on the following tabs:
Tab Action
Compatibility tab
n
For Certificate Authority, select Windows Server 2008 R2.
n
For Certificate Recipient, select Windows 7/Windows Server 2008 R2.
General tab
n
Change the template display name to True SSO.
n
Change the validity period to a period that is as long as a typical
working day; that is, as long as he user is likely to remain logged into
the system.
So that the user does not lose access to network resources while logged
on, the validity period must be longer than the Kerberos TGT renewal
time in the users domain.
(The default maximum lifetime of the ticket is 10 hours. To find the
default domain policy, you can go to Computer Configuration >
Policies > Windows Settings > Security Settings > Account Policies >
Kerberos Policy:Maximum lifetime for user ticket.)
n
Change the renewal period to 1 day.
Request Handling tab
n
For Purpose, select Signature and smartcard logon.
n
Select Allow private key to be exported.
n
Select, For automatic renewal of smart cards, …
Cryptography tab
n
For Provider Category, select Key Storage Provider.
n
For Algorithm name, select RSA.
Server tab
Select Do not store certificates and requests in the CA database.
IMPORTANT Make sure to deselect Do not include revocation information
in issued certificates. (This box gets selected when you select the first one,
and you have to deselect (clear) it.)
Issuance Requirements tab
n
Select This number of authorized signatures, and type 1 in the box.
n
For Policy type, select Application Policy and set the policy to
Certificate Request Agent.
n
For, Require the following for reenrollment, select Valid existing
certificate.
Security tab
For the security group that you created for the enrollment server computer
accounts, as described in the prerequisites, provide the following
permissions: Read, Enroll
a Click Add.
b Specify which computers to allow to enroll for certificates.
c For these computers select the appropriate check boxes to give the
computers the following permissions: Read, Enroll.
5 Click OK in the Properties of New Template dialog box.
6 Close the Certificate Templates Console window.
7 Right-click Certificate Templates and select New > Certificate Template to Issue.
NOTE This step is required for all certificate authorities that issue certificates based on this template.
8 In the Enable Certificate Templates window, select the template you just created (for example, True
SSO Template) and click OK.
View Administration
72 VMware, Inc.