how to duplicate a certificate template using a command?


i'm deploying nap , duplicate certificate template in certtempl.msc commands. i'm using windows server 2008 r2. , have installed enterprise ca , i'm working on ad.
duplicating template same requesting new template?
if yes, these commands have been trying

in file csr.inf typed:

[newrequest]
subject="cn=dc1,dc=contoso,dc=com"
exportable=true
keylength=2048
machinekeyset=true
friendlyname="manual certificate"
keyspec=1

[enhancedkeyusageextension]
oid=1.3.6.14.1.311.47.1.1

[extensions]
1.3.6.14.1.311.47.1.1="system health authentication"

[requestattributes]
certificatetemplate="workstation"

, in create new request
certreq -new csr.inf request.req

after try submit request using command
certreq -submit -config - -crl -rpc request.req certfileout.cert

but following error:
certificate not issued (denied) denied policy module 0x80094800, request certificate template is
not supported active directory certificate services policy: 1.3.6.1.4.1.311.21.8.1806387.4854250.11684030.1596675
3.1069840.122.1.30(workstation authentication)/workstation.

idea if approach correct , if not right approach?

no. microsoft don't support template duplication in other ways certificate templates (certtmpl.msc) mmc snap-in.
http://en-us.sysadmins.lv powershell pki module: http://pspki.codeplex.com/


Windows Server  >  Security



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group