Set Up Client Certificate Template Settings for NPS

In Cloudpath, certificate templates are used to generate certificates.
A template defines the properties embedded into a certificate when it is issued. Some properties are static and remain the same for every certificate. Other properties are calculated or use variables, allowing them to differ per certificate, based on user and device.

To set up a client certificate template using an onboard CA, perform the following steps:

  1. From the Cloudpath left menu, select Certificate Authority > Manage Templates.
  2. Click Add Template to create a new certificate template.
  3. Choose Use an onboard certificate authority and select the onboard CA you created in the previous section.
  4. Select Client Certificates.

    Create Client Certificate Template

  5. Select or enter a Username Decoration. The decoration of the username within the certificate allows RADIUS policies to be applied appropriately.
  6. Grant access for the appropriate amount of time.
    For example, you might have client certificate template for a guest user that is valid for one, or a few days, another for a contractor that is valid for 6 months, and one for employees that is good for a year.
    Tip: To configure pattern attributes, certificate strength, and EKUs, check the Configure Advanced Options box before you click Next.
  7. Select any email notifications to be sent to the user related to the lifecycle of the certificate.
    Additional certificate notifications can be configured after the template is created.
  8. Enter data in the RADIUS Options fields to assign a VLAN ID or Filter ID to certificates that use this template.
    These settings only apply if you are using the onboard RADIUS server.