| Table of Contents | ||
|---|---|---|
|
Prerequisites
The computer requesting the certificate must have Enroll permissions for the requested certificate template
Contact the Active Directory team for assistance with certificate template permissions
The requested certificate requires one or more values that are not supported by InCommon certificates such as:
Lifetimes exceeding 398 days
- EKUs
Extended Key Usages other than Digital Signature and Key Encipherment
Subject Alternate Names that are not in an approved DNS domain
Subject Alternate Names that are not DNS addresses such as an IP Address name
Submit the certificate request to an Austin CAs
Sign in to a computer joined to the Austin Active Directory where the computer has permissions to enroll for a certificate from the requested template
Start an administrative PowerShell session as a local
...
| Info |
|---|
Complete any remaining instructions in this PowerShell session unless directed otherwise |
administrator
Navigate to the path where the certificate request is stored.
Run the following commands to
...
retrieve the name of certificate request
...
:
Code Block
...
language powershell $Name = Read-Host -Prompt "Provide the name of the certificate request file"
Run the following commands
...
to retrieve the certificate to be imported:
Code Block
...
language powershell $Request = Get-ChildItem
...
| Where-Object { $_.Name -Match
...
$Name } | Sort-Object -Property LastWriteTime | Select-Object -Last 1
Run one of the following commands to set the certificate template:
For VMware SSL certificates, run the following:
Code Block
...
language powershell $Template = "VMwareSSL6.5"
For long-duration server certificates, run the following:
Code Block
...
language powershell $Template = "Server-10Year"
Run the following commands to define where the signed certificate file will be created using the certificate request file
Code Block
...
language powershell $Certificate =
...
$Request.FullName -
...
replace "$($Request.Extension)$", '.cer'Run the following commands to submit the request to
...
the Austin
...
Certificates service:
Code Block language powershell certreq -submit -attrib
...
"CertificateTemplate:$Template"
...
$Request.FullName $Certificate