Create PIV CS PKCS12 store (PIV PFX)
-
Create a new user in Active Directory, as follows:
- On the Microsoft CA machine, go to Start > Windows Administrative Tools > Active Directory Users and Computers. The Active Directory Users and Computers page appears.
- Right-click Users and select New > User. The New Object > User dialog box appears.
- Enter a First name, Last name, and User logon name and then click Next.
- Deselect User must change password at next logon.
- Enter and confirm a password.
- Click Next and then click Finish.
-
Open the Microsoft Management Console to add certificates snap-in, as follows:
- To open the Microsoft Management Console, right-click the Start menu, click Run, enter mmc in the Open field, and click OK.
- Go to File > Add/Remove Snap In.
- Click Certificates and select Add. The Certificate snap-in dialog box appears.
- Select My user account.
- Click Finish and click OK.
-
Double-click Certificates > Current User.
-
Right-click Personal and select All Tasks > Advanced Operations > Enroll on Behalf Of. The Certificate Enrollment Wizard opens.
-
Click Next. The Select Certificate Enrollment Policy page appears.
-
Click Browse to select a signing certificate. The Select a Certificate dialog box appears.
-
Click OK to select the certificate and close the dialog box. A certificate name appears in the Signing Certificate field.
-
Click Next. The Request Certificates page appears.
-
Select your PIV Content Signer (Device) certificate template and click Next. The Select a user page appears.
-
Enter the Username you created in step 1. Alternately, you can click Browse to display the Select User dialog box and search for the user.
-
Click Enroll and then click Close.
-
Select Certificates > Current User.
-
Double-click Personal and then double-click Certificates.
-
Right-click your user PIV-PIV Content Signer (Device) certificate and select All Tasks > Export. The Certificate Export Wizard opens.
-
Click Next. The Export Private Key page appears.
-
Select Yes, export the private key and click Next.
-
In the Export File Format page, do the following:
- Select Personal Information Exchange - PKCS #12 (PFX).
- Select Include all certificates in the certificate path if possible.
- Click Next. The Security page appears.
-
In the Security page, do the following:
- Select Password.
- Enter and confirm a certificate password.
- Click Next. The File to Export page appears.
-
In the File to Export page, enter a name for your certificate, for example, piv.
tipTip: Click Browse to browse to the location where you want to save your certificate, enter a File name and click Save.
-
Click Next and then click Finish.
-
Click OK on the Export successful confirmation prompt.
-
Copy this file. You need this file to Configure a Microsoft CA on Identity as a Service.