Skip to content

Managing Templates

Active Directory Certificate Services (AD CS) relies on certificate templates to define the properties and constraints of certificates issued by a Certification Authority (CA). Proper management of these templates ensures security, compliance, and operational efficiency. This section covers the processes for modifying, retiring, and maintaining certificate templates in a production environment.


Overview of Certificate Templates

Certificate templates in AD CS define the rules for issuing certificates, including subject name formats, validity periods, key usage, and enhanced key usage (EKU) settings. Templates are stored in the CA’s configuration and can be managed via the Certification Authority console or PowerShell. Each template corresponds to a specific use case, such as:
- Server Authentication (for SSL/TLS certificates)
- Client Authentication (for user authentication)
- Code Signing (for software integrity)
- Email Protection (for S/MIME)

Templates are associated with a CA and can be published or unpublished. Published templates are available for certificate enrollment, while unpublished templates are for editing.


Modifying Certificate Templates

Modifications to templates are required to align with evolving security policies or operational needs. Follow these steps:

Using the Certification Authority Console

  1. Open the Certification Authority console (certsrv.msc).
  2. Navigate to Certificate Templates > Active Templates.
  3. Right-click the template and select Edit.
  4. Modify properties such as:
  5. Subject Name (e.g., specify whether it’s required or optional).
  6. Validity Period (e.g., set a maximum lifetime).
  7. Key Usage (e.g., add or remove digital signature capabilities).
  8. Enhanced Key Usage (EKU) (e.g., specify allowed purposes like client authentication).
  9. Renewal (enable or disable certificate renewal).
  10. Click OK and republish the template if changes were made.

Using PowerShell

Use the Set-CATemplate cmdlet to modify properties. Example:

Set-CATemplate -Name "Web Server" -ValidityPeriod Years -ValidityPeriodLength 5
This updates the "Web Server" template to have a 5-year validity period.
Note: Some properties (e.g., template name) are read-only. Always test changes in a lab environment before applying them to production.


Retiring Certificate Templates

Retiring a template removes it from availability for enrollment while preserving its configuration for potential restoration.

Using the Certification Authority Console

  1. Open the Certification Authority console.
  2. Navigate to Certificate Templates > Active Templates.
  3. Right-click the template and select Retire.
  4. Confirm the action. The template is now marked as retired and cannot be used for enrollment.

Using PowerShell

Use the Remove-CATemplate cmdlet:

Remove-CATemplate -Name "Legacy Client" -Retire
Retired templates can be restored if needed, but this is a manual process and should be documented.


Best Practices for Managing Templates

  1. Test Changes in a Lab: Always validate modifications in a non-production environment to avoid unintended disruptions.
  2. Document Configuration: Maintain detailed records of template settings and their purposes for auditing and troubleshooting.
  3. Limit Permissions: Restrict editing/retiring rights to authorized administrators to prevent unauthorized changes.
  4. Audit Regularly: Periodically review templates for compliance with organizational policies and security requirements.
  5. Phase Out Legacy Templates: Retire outdated templates to reduce attack surfaces and ensure adherence to modern security standards.

Key takeaways

  • Certificate templates define critical certificate properties and must be managed carefully to ensure security and compliance.
  • Modifications require republishing templates, and some properties are immutable (e.g., template name).
  • Retiring templates disables enrollment but preserves configuration for potential restoration.
  • Always test changes in a lab environment and document all template configurations.
  • Regular audits and permission controls are essential for maintaining secure AD CS operations.