CIV Certificate Templates
New CA certificate templates dedicated to CIV Commercial Identity Verification can be defined in the CA. You can issue CIV cards with all the CAs that are supported by ActivID CMS.
Getting Started
-
Run mmc.exe to open the Microsoft Management Console.
-
On the File menu, click Add/Remove Snap-in.
-
In the Available snap-ins window, click Certificate Template, and then click Add.
-
Click OK.
-
In the console tree, expand your CA.

-
In the list of templates provided by default by Microsoft CA, right-click on Smartcard Logon template, and select Duplicate Template.
-
In the General tab, clear the Publish certificate in Active Directory option (if selected), and then click OK.
-
In the Request Handling tab, from the Purpose drop-down list, select Signature and smartcard logon.
-
Select the Prompt the user during enrollment option, and then click OK.
-
In the Cryptography tab, select the Algorithm name, Minimum key size (should be set to 2048), and Hash algorithm (should be set to SHA256). Then, click OK.
-
In the Extensions tab, in the Extension included in this template section, select Application Policies, and then click Edit.
-
In the Description of Application Policies box, verify that the Client Authentication and Smart Card Logon policies are present, and then click OK.
-
In the Extension included in this template section, select Issuance Policies.
-
Verify that no issuance policies are added.
-
In the Issuance Requirements tab, edit the settings as follows:
-
Select the This number of authorized signatures option. This allows ActivID CMS to issue a card. In the text box, enter the required number.
-
From the Application policy drop-down list, select Certificate Request Agent.
-
Select the Same criteria as for enrollment option.
-
Click OK.
-
-
In the Security tab, click Authenticated Users and, in the Allow column, select the Read and Enroll permissions. Then, click OK.

-
In the list of templates provided by default by Microsoft CA, right-click on the User template, and then select Duplicate Template.
-
Select a template, and then click OK.
-
In the Issuance Requirements tab, select This number of authorized signatures (if it is not already selected).
-
In the Request Handling tab, next to Purpose, select Signature.
-
In the Subject Name tab, select Supply in the request. The Subject Name is supplied by ActivID CMS.
-
For a Windows 2008 Server CA, configure the Minimum key size to 2048, and select the Hash algorithm (should be set to SHA256).
-
In the Extensions tab, in the Extension included in this template box, select Application Policies, and then click Edit.
-
In the Edit Application Policies Extension window, select the policy that you want to remove, and then click Remove.
-
Delete all policies, except the Client Authentication policy. Verify the Client Authentication description and then click OK.
-
Go back to the Extensions tab and select Issuance Policies, and then click Edit.
-
Verify that no issuance policies are added.
-
Click OK.

-
In the list of default templates provided by Microsoft CA, right-click on the User Signature Only template, and then select Duplicate Template.
-
Select a template, and then click OK.
-
In the Issuance Requirements tab, select the This number of authorized signatures option. This allows ActivID CMS to issue a card.
-
From the Application policy drop-down list, select Certificate Request Agent.
-
In the Subject Name tab, for CIV mode, select Build from this Active Directory information. Make sure that only E-mail name is selected to be included in the alternate subject name.
-
In the Security tab, in the Group or user name section, select Authenticated Users.
-
Select the Read and Enroll permissions.
-
In the Cryptography tab, for a Windows 2008 Server CA, configure the Minimum key size to 2048, and select the Hash algorithm (should be set to SHA256).
-
In the Request Handling tab, next to Purpose, select Signature.
-
Click OK.

-
In the list of default templates provided by Microsoft CA, right-click on the Exchange User template, and then select Duplicate Template.
-
In the Issuance Requirements tab, select the This number of authorized signatures option. This allows ActivID CMS to issue a card.
-
From the Application policy drop-down list, select Certificate Request Agent.
-
In the Subject Name tab, for CIV mode, select Build from this Active Directory information.
-
In the Request Handling tab, select the Encryption option.
-
In the Extensions tab, in the Extension included in this template section, select Issuance Policies.
-
Verify that no issuance policies are added.
-
In the General tab, select Publish certificate in Active Directory.
-
Click OK.