Skip to content

Templates Overview

Active Directory Certificate Services (AD CS) relies on certificate templates to define the rules and properties for certificates issued by a Certification Authority (CA). These templates act as blueprints, ensuring consistency, security, and compliance when certificates are created. By configuring templates, administrators control aspects like certificate validity, cryptographic usage, and access permissions, which are critical for securing services such as TLS, code signing, and authentication.


Purpose of Certificate Templates

Certificate templates standardize certificate issuance by specifying:
- Validity periods (e.g., how long a certificate remains valid).
- Key usage (e.g., whether the certificate can be used for encryption, signing, or authentication).
- Extended key usage (e.g., specific purposes like server authentication or email protection).
- Enrollment permissions (who can request certificates based on user or group membership).
- Revocation settings (e.g., whether certificates can be revoked and how they are published).

Templates are stored in Active Directory and applied to CAs (either standalone or enterprise CAs). They ensure that all certificates issued under a template adhere to predefined security policies.


Key Components of Certificate Templates

  1. Template Properties
  2. Validity Period: Defines the start and end dates for certificate lifetimes.
  3. Key Usage: Specifies cryptographic operations allowed (e.g., DigitalSignature, KeyEncipherment).
  4. Extended Key Usage (EKU): Adds granular constraints (e.g., Server Authentication, Client Authentication).
  5. Subject Name Format: Determines how the certificate’s subject is structured (e.g., User Principal Name or DNS Name).

  6. Security Settings

  7. Enrollment Permissions: Restricts certificate requests to specific users, groups, or roles.
  8. Enrollment Agents: Allows designated users to issue certificates on behalf of others.
  9. Revocation Enabled: Controls whether certificates can be revoked and how revocation lists are published.

  10. Template Enforcement

  11. Template Required: Forces the use of a specific template for certain services (e.g., requiring a Web Server template for HTTPS).
  12. Maximum Number of Certificates: Limits the total number of certificates that can be issued under the template.

Common Certificate Templates

  • Web Server: For SSL/TLS certificates (EKU: Server Authentication).
  • User: For end-user certificates (e.g., email encryption).
  • Code Signing: For signing software binaries (EKU: Code Signing).
  • Smart Card Logon: For secure authentication using smart cards.
  • Machine: For computer accounts (e.g., service account authentication).

These templates are pre-installed in AD CS but can be customized to meet organizational needs.


Managing Certificate Templates

Use the Certification Authority Management Console (MMC) or PowerShell cmdlets like Get-CATemplate and Set-CATemplate to configure templates. For example:

# List all certificate templates
Get-CATemplate

# View properties of a specific template
Get-CATemplate -Name "Web Server"

# Modify validity period
Set-CATemplate -Name "Web Server" -ValidityPeriod Years -ValidityPeriodLength 5

To check enrollment permissions:

# Get enrollment permissions for a template
Get-ADPermission -Identity "CN=Web Server,CN=Certificate Templates,CN=PolicyStores,CN=Configuration,DC=example,DC=com"

Key takeaways

  • Certificate templates enforce consistency and security in certificate issuance.
  • They define cryptographic usage, validity, and access controls.
  • Templates are critical for securing services like TLS, code signing, and authentication.
  • Use PowerShell or the Certification Authority MMC to configure and manage templates.
  • Always align template settings with organizational security policies and compliance requirements.