Skip to main content

2026 年 8 月 24 日

Add the Root Certificate to the Enterprise NTAuth Store

If you use a CA to issue smart card login or domain controller certificates, you must add the root certificate to the Enterprise NTAuth store in Microsoft Active Directory. You do not need to perform this procedure if the Windows domain controller acts as the root CA.

Procedure

  1. On your Active Directory server, use the certutil command to publish the certificate to the Enterprise NTAuth store.

    For example: certutil -dspublish -f path_to_root_CA_cert NTAuthCA

Results

The CA is now trusted to issue certificates of this type.

此頁面對您有幫助嗎?

針對本主題提供意見回饋

本主題對您有幫助嗎?

請勿填寫任何個人或機密資訊。

正在產生連結…