Share via


Install and Use the Certification Authority Snap-In

Applies To: Windows Server 2008

The Certification Authority snap-in can be used to administer a certification authority (CA) on this computer or on another computer. The snap-in is installed automatically on a computer where a CA has been installed. Otherwise, you must first install the Active Directory Certificate Services (AD CS) Remote Server Administration Tools.

You must be a CA administrator to complete this procedure. For more information, see Implement Role-Based Administration.

To administer a CA on this computer

  1. If this is the first time you are using the Certification Authority snap-in on this computer, click Start, click Run, type mmc, and then press ENTER.

  2. On the File menu, click Add/Remove Snap-in.

  3. Add the Certification Authority snap-in to the list on the right.

  4. Select the computer hosting the CA that you want to administer, and then click OK.

You can also use an existing instance of the Certification Authority snap-in to switch from administering one CA to administering another CA.

You must be a CA administrator on the remote CA to complete this procedure. For more information, see Implement Role-Based Administration.

To administer a CA on another computer

  1. Open the Certification Authority snap-in.

  2. On the Action menu, click Retarget Certification Authority.

  3. Click Another computer, and type the name of the computer.

You can also customize the Certification Authority snap-in by using display filters. With filters, you can restrict the items displayed in the details pane of the Certification Authority snap-in to items that meet a set of criteria you establish. For example, you can create a filter that will display in the Issued Certificates folder only those certificates that were effective after a specific date.

You do not need to be a CA administrator, but you must have permissions to perform administration tasks on the CA to complete this procedure. For more information, see Implement Role-Based Administration.

To set display filters for the Certification Authority snap-in

  1. Open the Certification Authority snap-in.

  2. Click any of the displayed folders except Certificate templates.

  3. On the View menu, click Filter.

  4. For each of the selection criteria:

    • Click Add.

    • In Field, click the field on which to filter.

    • In Operation, click the operation to qualify the filter value for this field.

    • In Value, type the qualification value.

  5. To remove a filter, click it in the Filter dialog box, and then click Remove.

  6. To remove all existing filters, in the Filter dialog box, click Reset.

The Remote Server Administration Tools can be installed on a computer running Windows ServerĀ® 2008 by using the Add Features Wizard.

You must be an administrator on the server to complete this procedure. For more information, see Implement Role-Based Administration.

To install the AD CS Remote Server Administration Tools

  1. Open Server Manager.

  2. Under Features Summary, click Add Features to start theAdd Features Wizard.

  3. On the Select Features page, click the plus sign that appears to the left of the Remote Server Administration Tools check box, and then click the plus sign to the left of the Role Administration Tools check box.

  4. Select the Active Directory Certificate Services check box, click Next, and then click Install.

  5. When installation is complete, click Close.

To perform remote administration tasks from a computer running Windows Vista, you can obtain the Remote Server Administration Tools Pack from the Microsoft Download Center (https://go.microsoft.com/fwlink/?LinkId=89361).

Additional references