To create a new certificate template
1
On the computer with the certification authority installed, click Start > Run.
2
In the Open box, type
mmc
, and then click OK.
3
In the Microsoft Management Console, click File > Add/Remote Snap-in.
4
Click Add.
5
Click Certificate Templates, click Add, and then click Close.
6
Click Certificate Templates, and then click OK.
7
In the Microsoft Management Console tree, click Console Root > Certificate
Templates.
8
In the right pane, right-click the User template, and then click Duplicate
Template.
9
Type the template display name.
For example, type
AMT Mutual
10
Check Publish certificate in Active Directory.
11
On the Request Handling tab, check Allow private key to be exported.
12
Click CSPs.
13
In the CSP Selection dialog box, under CSPs, check Microsoft Strong
Cryptographic Provider, and then click OK.
14
On the Subject Name tab, click Supply in the request.
15
On the Security tab, grant the Read, Write, and Enroll permissions to both
the Domain Admins group and the Notification Server’s Application Identity
account.
16
On the Extensions tab, click Application Policies, and then click Edit.
17
In the Edit Application Policies Extension dialog box, click Add, and then
add the Server Authentication policy.
18
In the Edit Application Policies Extension dialog box, click Server
Authentication, and then click Edit.
19
Verify that the Object identifier is
1.3.6.1.5.5.7.3.1
, and then click Cancel.
20
Click Add once more, and then, in the Add Application Policy dialog box,
click New.
21
In the New Application Policy dialog box, in the Name box, type a name for
the policy.
For example, type
TLS Mutual Authentication
Configuring TLS
Configuring TLS with mutual authentication
102