共用方式為


Install the Certificate Templates Snap-In

Applies To: Windows Server 2008

The Certificate Templates snap-in allows you to view and manage critical information about all the certificate templates in a domain.

Important fields in the Certificate Templates snap-in include:

  • Template Display Name. This field describes the purpose of the certificate. When an organization creates a custom certificate template, it may be useful to use a naming convention that helps administrators identify the certification authority (CA) or portion of the organization associated with the template.

  • Minimum Supported CAs. The configurable options in Windows-based certificate templates have been expanded from Windows 2000 to Windows Server 2003 and in Windows Server® 2008. Therefore, not all certificate templates are supported by all Windows Server–based CAs.

  • Version. If certificate template configurations evolve over time, the ability to track version information becomes important for compatibility and support.

You must be a local administrator to install the Certificate Templates snap-in and a member of Domain Admins to use the Certificate Templates snap-in. For more information, see Implement Role-Based Administration.

To install the Certificate Templates snap-in

  1. Click Start, click Run, and then type mmc.

  2. On the File menu, click Add/Remove Snap-in.

  3. On the Add and Remove Snap-ins dialog box, double-click the Certificate Templates snap-in to add it to the list. Click OK.

By default, the Certificate Templates snap-in is installed automatically when a CA is installed on a server. The Certificate Templates snap-in can be installed on a different server by using Server Manager to install Active Directory Certificate Services (AD CS) tools.

You must be local administrator to install Remote Server Administration Tools. You must be a member of Domain Admins to access and administer certificate templates for a domain. For more information, see Implement Role-Based Administration.

To administer certificate templates from a remote server

  1. Open Server Manager.

  2. Under Features Summary, click Add Features.

  3. Expand Remote Server Administration Tools and Role Administration Tools.

  4. Select the Active Directory Certificate Services check box, click Next, and then click Install.

  5. When the installation process is finished, click Close.

  6. Click Start, type mmc, and press ENTER.

  7. On the File menu, click Add/Remove Snap-in.

  8. Click the Certificate Templates snap-in, click Add, verify that the domain controller hosting the certificate templates you want to manage is selected, and then click OK.

You can use the Certificate Templates snap-in to manage certificate templates in a different domain.

You must be a domain or enterprise administrator for the other domain to complete this procedure. For more information, see Implement Role-Based Administration.

To manage certificate templates in a different domain

  1. Right-click the Certificate Templates snap-in, and click Connect to another writable domain controller.

  2. To type the name of a different domain, click Change. To select a different domain controller for the existing domain, click Select a Writable Domain Controller.

  3. If you have previously selected an alternate domain controller, you can revert to the original domain controller by clicking Default Writable Domain Controller.

Additional references