2. Creating 4 new Certificate Templates
Create the VPN server certificate template - IKEv2
- Logon to your PKI server
- Open up Certificate Authority > right click Certificate Templates > Manage
- Right click RAS and IAS Server template and select Duplicate Template
- General tab - Template display name: Clientname VPN Server Authentication
- Extensions tab - Select Applications > Edit > Add > IP security IKE intermediate
- Security tab - Add AOVPN RRAS Servers group and grant it Read and Enroll permissions
- Security tab - Remove RAS and IAS Servers group
- Subject name tab - Check Supply in the request
- Click OK to save
Create NPS server certificate template
- Right click RAS and IAS Server template and select Duplicate Template
- General tab - Template display name: Clientname NPS Server Authentication
- Security tab - Add AOVPN NPS Servers group and grant it Read, Enroll and Autoenroll permissions
- Security tab - Remove RAS and IAS Servers group
- Compatibility tab - select Windows Server 2012 R2 for certificate authority
- Compatibility tab - select Windows 8.1/Windows Server 2012 R2 for certificate recipient
- Click OK to save
Create User Authentication Certificate template
- Right-click User and select Duplicate Template
- General tab - Template display name: Clientname VPN User Authentication
- General tab - Clear the Publish certificate in Active Directory check box
- Security tab - Add AOVPN Users group and grant it Read, Enroll and Autoenroll permissions
- Security tab - Remove the Domain Users group
- Compatibility tab - select Windows Server 2012 R2 for certificate authority
- Compatibility tab - select Windows 8.1/Windows Server 2012 R2 for certificate recipient
- Request Handling tab - Clear the Allow private key to be exported check box
- Cryptography tab - Change provider category to Key Storage Provider
- Cryptography tab - Check Requests must use one of the following providers
- Cryptography tab - Select the Microsoft Platform Crypto Provider check box
- Subject name tab - Uncheck Include e-mail name in the subject name and E-mail name
- Click OK to save
Create Computer Authentication Certificate template
- Right-click Computer template and Duplicate Template
- General tab - Template display name: Clientname VPN Computer Authentication
- Compatibility tab - select Windows Server 2012 R2 for certificate authority
- Compatibility tab - select Windows 8.1/Windows Server 2012 R2 for certificate recipient
- Security tab - Add AOVPN Computers group and grant it Read, Enroll and Autoenroll permissions
- Security tab - Remove the Domain Computers group
- Click OK to save
Publish the newly created certificate templates
- Right-click Certificate Templates > New > Certificate Template to Issue > select:
- Clientname VPN Server Authentication
- Clientname NPS Server Authentication
- Clientname VPN User Authentication
- Clientname VPN Computer Authentication