6
Click OK.
7
In the tree, click Console Root > Certificate Templates.
8
In the right pane, right-click the User template, and then click Duplicate
Template.
9
Type the template display name.
For example, type
AMT Remote Configuration
.
10
Check Publish certificate in Active Directory.
11
On the Request Handling tab, check Allow private key to be exported.
12
On the Request Handling tab, click CSPs.
13
In the CSP Selection dialog box, under CSPs, check Microsoft Strong
Cryptographic Provider, and then click OK.
14
On the Subject Name tab, click Supply in the request.
15
On the Security tab, grant Read, Write, and Enroll permissions to both the
Domain Admins group and the Notification Server’s Application Identity
account.
For more information about the Notification Server’s Application Identity
account, see the Symantec Management Platform Help.
16
On the Extensions tab, click Application Policies, and then click Edit.
17
In the Edit Application Policies Extension dialog box, click Add, click Server
Authentication, and then click OK.
18
In the Edit Application Policies Extension dialog box, click Server
Authentication, and then click Edit.
Verify the Object identifier is
1.3.6.1.5.5.7.3.1
and then click Cancel.
19
Click Add once more, and then, in the Add Application Policy dialog box,
click New.
20
In the New Application Policy dialog box, in the Name box, type a name for
the new application policy.
For example, type
AMT Remote Configuration OID
.
21
In the Object identifier box, type
2.16.840.1.113741.1.2.3
and then click
OK.
22
Click the application policy you just created (in this example, click AMT
Remote Configuration OID), and then click OK.
23
Click OK.
24
Click OK to save and close the properties of the new template.
71
Configuring Intel AMT computers for out-of-band management
Configuring Intel AMT computers for out-of-band management