Entrust PKI as a Service

Selecting CAs for certificate templates

Once started, the on-premises agent discovers:

  • The Microsoft Windows domains for each Active Directory node (see Adding Active Directory nodes).
  • The Microsoft certificate templates configured on each domain

See below for how to select the PKIaaS certificate authority that will issue certificates for each template.

To select a CA for a certificate template:

  1. Follow the steps described in Accessing your partitions to log into the PKIaaS interface as a user with any of these roles:

  2. Click Certificate Authorities in the sidebar.

    PNG

  3. Select the Enrollment Protocols tab.

    PNG

  4. Click WSTEP in the protocols list.

  5. In the Active Directories tab, click on an Active Directory name.

    PNG

  6. On the Discovered Domains tab, check the domains discovered by the agent for the Active Directory.

    PNG

  7. On the Certificate Templates tab, select Actions > Edit Certificate Template for a certificate template.

    PNG

  8. Select one of the certificate authorities described in Configuring an issuing CA for WSTEP and click Edit.