Entrust PKI as a Service

Importing the WSTEP certificate chain

Import the WSTEP certificate chain into the GPO previously created in Creating a Group Policy Object.


ℹ See Downloading the certificate chain for how to download the required certificates.


To import the certificate chain into the GPO:

  1. Log in to the root Active Directory of the forest as an Active Directory administrator.

  2. Select Start > Windows Administrative Tools > Group Policy Management to open the Group Policy Management dialog.

    PNG

  3. Right-click the Group Policy Object.

  4. Select Edit to display the Group Policy Management Editor.

    PNG

  5. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies.

  6. Right-click Trusted Root Certificate Authorities and select Import.

    PNG

  7. In the Certificate Import Wizard, click Next and select the root CA certificate file to import.

  8. Click Next to reveal the Certificate Store settings.

    PNG

  9. Verify that the selected certificate store is Trusted Root Certification Authorities.

  10. Click Next to display the Completing the Certificate Import Wizard.

  11. Click Finish to return to the Group Policy Management dialog.

  12. In the Group Policy Management dialog, navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies.

  13. Right-click Intermediate Certificate Authorities and select Import to display the Certificate Import Wizard.

  14. Click Next and select the issuing CA certificate file to import.

  15. Click Next to reveal the Certificate Store settings.

  16. Verify that the selected certificate store is Intermediate Certification Authorities.

  17. Click Finish.

  18. Select File > Exit to close the Group Policy Management Editor.