Sep
06
2010
Domain Controller certificates: Kerberos Authentication template
When you install Windows 2008 Certification Authority a new domain controller certificate template named Kerberos Authentication is available. It replaces the Domain Controller Authentication template. If you need more information about the new certificate templates shipped with a Windows 2008 CA you can read this article.
Here is a tab that outlines the specific attributes of the Domain Controller Authentication and Kerberos Authentication templates:
| Domain Controller Authentication | Kerberos Authentication | |
| Key Usage | Client Authentication
Server Authentication Smart Card Logon |
Client Authentication
Server Authentication Smart Card Logon KDC Authentication. |
| Subject Alternate Name | DNS Name : Domain Controller FQDN. | DNS Name : Domain FQDN.
DNS Name : Domain NetBios name. |