> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create the Smartcard Logon Template

1. Log onto the certificate authority server, then launch the Microsoft Management Console (MMC) and click **File** then **Add/Remove Snap-in**.

   <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/8a3829f53042a69478bc1cf3e76474adbb02971bbecae5f27da3f52a2761dcf5-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=05c56a3c4a0fc9e3cb95dd6d2237ea21" alt="" width="2836" height="1450" data-path="images/docs/8a3829f53042a69478bc1cf3e76474adbb02971bbecae5f27da3f52a2761dcf5-image.png" />

2. In the "Add or Remove Snap-ins" list, choose **Certificate Templates**, then click **Add**. 

   <img src="https://mintcdn.com/truu-2/L38yxuvvUa8uAW5I/images/docs/0d6841cc6185a5805845a3b6323184b6725a3e21cb548605284809438e070c7b-image.png?fit=max&auto=format&n=L38yxuvvUa8uAW5I&q=85&s=e564cde9704bf0087387d9c77e10e3c6" alt="" width="1684" height="1193" data-path="images/docs/0d6841cc6185a5805845a3b6323184b6725a3e21cb548605284809438e070c7b-image.png" />

3. Double-click on the **Certificate Template** under **Selected snap-ins,** then right click on the **Smartcard Login** template. Choose **Duplicate Template**.

   <img src="https://mintcdn.com/truu-2/rjjBxA7Z_Wk_-34G/images/docs/d8bb805072bbb0000da418a631c4dafecedc08b634504b2c94b5033a878c0388-image.png?fit=max&auto=format&n=rjjBxA7Z_Wk_-34G&q=85&s=f00e3b129f451f9dffa5ef43ff4502da" alt="" width="986" height="359" data-path="images/docs/d8bb805072bbb0000da418a631c4dafecedc08b634504b2c94b5033a878c0388-image.png" />

4. Navigate to the **Compatibility** tab and check to make sure the operating system versions of the **Certificate Authority** and **Certificate recipient** are appropriately selected for your environment.   

   <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/8d8372c86207494dc7fd7fbfd6800ca1e4a9ff01c2853202b3dc4101be45473a-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=c84f2ddfeb0cec00ecfb45c3377c1a18" alt="" width="1003" height="1402" data-path="images/docs/8d8372c86207494dc7fd7fbfd6800ca1e4a9ff01c2853202b3dc4101be45473a-image.png" />

5. In the **General** tab, create a **Template Display Name** for the template, then select **Publish certificate in Active Directory**. Additionally, specify the appropriate template validity and renewal period for your environment.  I.E \_TruUSmartCardLogon

**NOTE: Do not leave any spaces in the name of the Template display name.  Also the Publish certificate in Active Directory is optional if your company policy doesn’t allow this**. 

<img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/a8ab0e4c772218a450b11e45fb9a09833509e0c2065e0a197860acdd7bf6a4de-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=0b5021b2d5b73ce885744e8bc1376349" alt="" width="995" height="1398" data-path="images/docs/a8ab0e4c772218a450b11e45fb9a09833509e0c2065e0a197860acdd7bf6a4de-image.png" />

    6. Navigate to the **Issuance Requirements** tab, select **This number of authorized signatures** checkbox and set the number of authorized signatures to *1*. Then, select **Policy type required in signature** setting **to Application Policy** and the **Application Policy** setting to **Certificate Request Agent**. 

<img src="https://mintcdn.com/truu-2/rjjBxA7Z_Wk_-34G/images/docs/f4c8b645777acede0865e4ebde89f35b9900f7ec7a7fd71dd9823e291affdb1e-image.png?fit=max&auto=format&n=rjjBxA7Z_Wk_-34G&q=85&s=81465c59dbafd699801472cfc0cf07ef" alt="" width="982" height="1385" data-path="images/docs/f4c8b645777acede0865e4ebde89f35b9900f7ec7a7fd71dd9823e291affdb1e-image.png" />

7. Navigate to the **Cryptography** tab and set the following settings for **Key Storage Provider** (KSP) support:

   <img src="https://mintcdn.com/truu-2/m22YLP0oXSNG0U3O/images/docs/6e2cff652d5e7d52784df17b8dd7332ed8efce8d2ace14c4c482f5f21912aa09-image.png?fit=max&auto=format&n=m22YLP0oXSNG0U3O&q=85&s=d35e0f7e5d152062b03db96722389959" alt="" width="395" height="555" data-path="images/docs/6e2cff652d5e7d52784df17b8dd7332ed8efce8d2ace14c4c482f5f21912aa09-image.png" />

8. Navigate to the **Security** tab, add the **Server that the CA Adapter is Installed on** with **Read**, **Write** and **Enroll** permissions. Then, select the **TruU service account** with **Read**, **Write** and **Enroll** permissions. Click **Apply** to complete setup in this tab. Then, click **OK**.   

<img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/c536d89771d939964435c6f9e929ebc05fe3a1b3f482f5bf9484ba0d30ae853e-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=32f058f248f1a91ac74175501d5e2255" alt="" width="666" height="458" data-path="images/docs/c536d89771d939964435c6f9e929ebc05fe3a1b3f482f5bf9484ba0d30ae853e-image.png" />

9. Next, navigate to your **Certificate Authority** tab and click the **Certificate Templates** folder. Right-click on the folder and choose **New** then **Certificate Template to Issue**.

<img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/9bdbb36f0149efd8230097eeffbd63d2a17b7af6ee8fbf6b4eb7945a270e2ece-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=e41371a8ae96ec3f319a36eba1c4836a" alt="" width="1872" height="1306" data-path="images/docs/9bdbb36f0149efd8230097eeffbd63d2a17b7af6ee8fbf6b4eb7945a270e2ece-image.png" />

10. Select the **TruUSmartcardLogon** template, then click **OK**.

<img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/cf1b2d2c79070a6df8d36f11ad484910209a440a605bc1928d7b44668cbf9f2d-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=8b4fe5133f51c3f17b8b120a2c0c59a9" alt="" width="1438" height="916" data-path="images/docs/cf1b2d2c79070a6df8d36f11ad484910209a440a605bc1928d7b44668cbf9f2d-image.png" />

11. Right-click on the new **TruUSmartcardLogon** template to verify its properties are set. Then, click **OK**.

**Note**: The **"Smart Card Logon"** and **"Client Authentication"** intended purposes are configured for this certificate template.

<img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/a34646fcccb180f970c05663444b424187c0b621470655d09b92f3226cf5dfff-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=45c5428b039ac2356dee69cbd82b7b6f" alt="" width="2078" height="1153" data-path="images/docs/a34646fcccb180f970c05663444b424187c0b621470655d09b92f3226cf5dfff-image.png" />

***

[Create Enrollment Agent Computer Template](/docs/create-the-computer-template)

[Create Enrollment Agent Certificate](/docs/requesting-enrollment-agent-certificate)
