Create the PIV - Key Management template
-
On the Microsoft CA machine, go to Start > Windows Administrative Tools > Certification Authority.
-
Click your Certificate Authority to expand the root folder.

-
To set the user permissions, right-click Certificate Templates, and then select Manage. The Certificate Templates Console appears.

-
Scroll the template list, right-click the PIV - PIV Authentication template and select Duplicate Template. The Properties of New Template dialog box appears.

-
Click the General tab, and configure the following settings:
- In the Template display name field, enter PIV - Key Management. The Template name field is filled in automatically with the template display name (with no spaces).
- Select Publish certificate in Active Directory.
-
Click the Request Handling tab, and do the following:
-
From the Purpose drop-down list, select Encryption.
When asked to confirm the change, click Yes.

-
Optional. If you want the key to be archived and available for recovery, select Archive the subject's private key.
-
-
Click the Extensions tab.
-
Select Application Policies, and then click Edit. The Edit Application Policies Extension dialog box appears.
-
Add the Secure Email policy to the list of application policies, as follows:
- On the Edit Application Policies Extension dialog box, click Add. The Add Application Policy dialog box appears.
- Scroll the Application policies list and select Secure Email, and then click OK.
-
On the Edit Application Policies Extension dialog box, remove the application policies that are not required.
- Select Any Purpose and click Remove.
- Select Client Authentication and click Remove.
- Select Smart Card Logon and click Remove.
- Click OK to close the dialog box.
-
In the Extensions tab, select Issuance Policies and then click Edit. The Edit Issuance Policies dialog box appears.
-
On the Edit Issuance Policies dialog box, select
id-fpki-common-authenticationand then click Remove. -
Click OK to close the dialog box.
-
If you selected to Publish certificate in Active Directory, do the following:
- Click the Issuance Requirements tab.
- Select The number of authorized signatures and enter 1 in the text box.
- From the Policy type required in signature drop-down list, select Application policy.
- From the Application policy drop-down list, select Certificate Request Agent.
-
Click OK to close the Properties dialog box.
The PIV - Key Management certificate template is added to the list of templates.