Manage Certificate Enrollment Policy by Using the Certificates Snap-in
This topic describes the procedures and applications used to add enrollment policy servers and manage enrollment policies by using the Certificates snap-in. These procedures can be used to configure enrollment policies that enable users to request certificates from commercial certification authoriti...
Submit a User Certificate Request over the Web
When you request certificates from a Windows-based stand-alone certification authority (CA), you use the CA Web enrollment pages. Web enrollment pages can also be used to request certificates from enterprise CAs if you want to set optional request features that are not available in the Certificate R...
Request a Certificate Over the Web
Certification authorities (CAs) can be accessed by using CA Web enrollment pages, which can be used to perform a variety of tasks related to requesting certificates. The default location of the CA Web enrollment pages is http:// servername /certsrv, where servername is the name of the server that ho...
Certificate Enrollment Policy Servers
Certificate enrollment policy provides the locations of certification authorities (CAs) and the types of certificates that can be requested. Organizations that are using Active Directory Domain Services (AD DS) can use Group Policy to provide certificate enrollment policy to domain members by using ...
Check on a Pending Certificate Request
When you submit a certificate request to a Windows-based enterprise certification authority (CA), it is immediately processed and will either be issued or denied, unless the certificate template has been configured to require approval by a certificate manager. When you submit a certificate request t...
Enroll for Certificates on Behalf of Other Users
It is not always possible for users to enroll for a certificate on their own behalf. This can be the case for a user smart card certificate. By default, only domain administrators are granted permission to request a certificate on behalf of another user. However, a user other than a domain administr...
Submit an Advanced Certificate Request over the Web
The policy of a certification authority (CA) determines the types of certificates a user can request and the options they can configure. If enabled, you can use the Advanced Certificate Request Web page to set the following options for each certificate requested: Certificate template (from an enterp...
Request a Certificate by Using a PKCS #10 or PKCS #7 File
It is not always possible to submit a certificate request online to a certification authority (CA). In these instances, you might still be able to submit a certificate request in the form of a PKCS #7 or PKCS #10 file. In general, you use a PKCS #10 file to submit a request for a new certificat...
Registration Authorities
A registration authority is a computer that is configured for an administrator to request and retrieve issued certificates on behalf of other users. A registration authority does not have to be installed on the same computer as the certification authority for which it processes certificate requests....
Renew a Certificate with the Same Key
Renewing a certificate with the same key provides maximum compatibility with past uses of the accompanying key pair, but it does not enhance the security of the certificate and key pair. Users or local Administrators is the minimum group membership required to complete this procedure. Review the det...
Renew a Certificate with a New Key
Renewing a certificate with a new key allows you to continue using an existing certificate and its associated data, while enhancing the strength of the key associated with the certificate. This can be desirable if using a new certificate would cause disruption and the existing certificate has not be...
Display Certificate Stores
Using the Certificates snap-in, you can display the certificate store for a user, a computer, or a service according to the purpose for which the certificates were issued or by using their logical storage categories. When you display certificates according to their storage categories, you can also c...
Renew a Certificate
Every certificate has a validity period. After the end of the validity period, the certificate is no longer considered an acceptable or usable credential. The Certificates snap-in enables you to renew a certificate issued from a Windows enterprise certification authority (CA) before or after the end...
View Certificates
Certificates can be issued and used for many purposes. It can be useful to examine certificate stores, certificate information and properties, and information about archived and revoked certificates. Display Certificate Stores View Certificate Information View Certificate Properties View the Certifi...
Display Certificates by Logical Certificate Stores
Logical certificate stores organize certificates in logical, functional categories for users, computers, and services. The use of logical certificate stores eliminates the need to store duplicates of common public key objects, such as trusted root certificates, certificate trust lists (CTLs), and ce...
General Tab
You can view information about the fields, extensions, and properties that define an issued certificate by double-clicking any certificate displayed in the certificate store. Clicking the General tab provides a general overview of the certificate, including the following information: Supported uses ...
Display Certificates by Certificate Purpose
You can view and inspect certificates based on what they are intended to be used for, such as client authentication or key recovery, rather than on their logical roles. Users or local Administrators is the minimum group membership required to complete this procedure. Review the details in "Additiona...
View Certificate Information
Double-click a certificate to view its properties and intended uses. This information is displayed on three tabs: General , Details , and Certification Path . General Tab Details Tab Certification Path Tab ⇒⇒ Certificate Manager "certmgr.msc" Manual
Learn More About Certificate Stores
Windows stores a certificate locally on the computer or device that requested it or, in the case of a user, on the computer or device that the user used to request it. The storage location is called the certificate store. A certificate store often has numerous certificates, possibly issued from a nu...
Certification Path Tab
Using the Certification Path tab, you can view the path from the selected certificate to the certification authorities (CAs) that issue the certificate. Before a certificate is trusted, Windows must verify that the certificate comes from a trusted source. This verification process is called path val...
View Certificate Properties
The Certificate Properties dialog box displays certificate property values on four tabs. Certificate Properties General Tab Certificate Properties Cross-Certificates Tab Certificate Properties OCSP Tab Certificate Properties Extended Validation Tab ⇒⇒ Certificate Manager "certmgr.msc" Manual
Certificate Validity Periods
The Certificates snap-in enables you to renew a certificate issued from a Windows-based enterprise certification authority (CA) before or after the end of its validity period by using the Certificate Renewal Wizard. About certificate validity Every certificate has a validity period. After the end of...
Details Tab
The Details tab provides the following information about the certificate: Version . The X.509 version number. Serial number . The unique serial number that the issuing certification authority (CA) assigns to the certificate. The serial number is unique for all certificates issued by a given CA. Sign...
Hash Algorithms
A hash algorithm is an algorithm that produces a hash value of a piece of data, such as a message or session key. With a good hash algorithm, changes in the input data can alter every bit in the resulting hash value. For this reason, hashes are useful in detecting any modification in a data object, ...
