Description

Generating and Loading on a Smart Card, a Private Key and Personal Certificate From a Microsoft CA

Symptoms


Solution

This article describes how to generate and load a key pair and personal certificate on a smart card using the Microsoft Certificate Server, which is part of Windows 2000 Advanced Server. A similar process is required to obtain a certificate from any Certificate Authority (CA). Once your smart card software is installed and operational, go to the Microsoft CA Server page to generate a private key and personal certificate. In this configuration example, a Schlumberger smart card is used.

To generate and load a private key and personal certificate from a Microsoft CA, perform the following steps:

alt Access the Microsoft CA server software welcome page.

alt In the Select a Task area, click Request a Certificate , and then click Next .

alt From the Choose Request Type dialog box, click on Advanced request, and then click Next .

alt If you are requesting a certificate for your own smart card, from the Advanced Certificate Requests dialog box, select Submit a Certificate Request to this CA using a form, and then click Next . Proceed to Step 6.

alt If you are enrolling on behalf of another user, select Request a Certificate for a smart card on behalf of another user using the Smart Card Enrollment Station , and then click Next .

note In large deployments, the administrator may wish to generate key pairs on smart cards prior to deploying them to users. Most CAs, Microsoft included, allow you to enroll a certificate on a smart card on behalf of another user. When you select this option, the user's information must be correctly entered. Inform the users of the pre-selected password and have them change it later.

alt Under Identifying Information , enter the following identifying information:
  • Name
  • Email
  • Company
  • Department
  • City
  • State
  • Country/Region
alt From the Intended Purpose list, click to select IPSec Certificate .

alt From the CSP list, select Schlumberger Cryptographic Service Provider .

alt In the Key Options area, accept the following default settings:
  • Key Usage : Both
  • Key Size : 1024
  • Create new key set
alt Click Submit . Your smart card will now generate a private key and certificate request.

alt If your smart-card software prompts for your password or PIN during key generation, enter it. The default PIN on Schlumberger smart cards is 00000000. Your key will now be generated.

note This process may take up to 2 minutes depending on the performance of your hardware.

alt If your Microsoft CA Server is configured to automatically approve certificates, the message 'The certificate you requested was issued to you' will display on the Certificate Issued page. Click Install this Certificate .

alt If your CA does not auto-approve, you may have to wait for the administrator to approve your certificate request. After your administrator approves your certificate request, return to the CA Server web page and retrieve your certificate.

alt Load a CA for a smart card. For more information, go to Loading a CA Certificate for a Smart Card [juniper.net] .

Former Article Id

ns10417