The process involves creating and making available two custom Microsoft CA templates: one for Machine SSL and Solution User certificates, and one for VMCA as a Subordinate CA.
Create Template for Machine SSL and Solution User Certificates
This template is for certificates used by vSphere components like the Machine SSL certificate and Solution User certificates.
- Connect to the CA server via RDP.
-
Open the Certificate Template Console by clicking Start > Run, typing certtmpl.msc, and clicking OK.
- Right-click the Web Server template and select Duplicate Template.
- In the Duplicate Template window, select Windows 7 / Server 2008 R2 Enterprise for broad compatibility.
- Note: If a higher encryption level than SHA1 is required, select Windows Server 2012 Enterprise.

- Go to the General tab and enter vSphere 8.x in the Template display name field.
- Go to the Extensions tab.
- Select Application Policies and click Edit.
- Select Server Authentication and click Remove, then OK.
- Note: If Client Authentication is present, remove it as well.
- Select Basic Constraints and click Edit.
- Select the Enable this extension check box and click OK.
- Select Key Usage and click Edit.
- Select Signature is proof of origin (non repudiation). Keep other settings at their default.
- Click OK.
- Go to the Subject Name tab.
- Ensure the Supply in the request option is selected.
- Click OK to save the template.
- Next, make the template available for issuance by following the steps in Adding a new template to certificate templates.
Create Template for VMCA as a Subordinate CA
This template is used when configuring VMCA to act as a Subordinate CA to your Microsoft CA.
- Connect to the CA server via RDP.
-
Open the Certificate Template Console by clicking Start > Run, typing certtmpl.msc, and clicking OK.
- Right-click the Subordinate Certificate Authority template and select Duplicate Template.
- In the Duplicate Template window, select Windows 7 / Server 2008 R2 Enterprise for broad compatibility.
- Note: If a higher encryption level than SHA1 is required, select Windows Server 2012 Enterprise.

- Go to the General tab and enter vSphere 8.x VMCA in the Template display name field.
- Ensure Publish certificate in Active Directory is selected.
- Go to the Extensions tab.
- Select Basic Constraints and click Edit.
- Select the Enable this extension check box and click OK.
- Select Key Usage and click Edit.
- Ensure the following options are enabled: Digital Signature, Certificate signing, and CRL signing.
- Ensure Make this extension critical is enabled.
- Click OK.
- Click OK to save the template.
- Next, make the template available for issuance by following the steps in Adding a new template to certificate templates.
Adding a new template to certificate templates
- Connect to the CA server via RDP.
- Open the Certification Authority console by clicking Start > Run, typing certsrv.msc, and clicking OK.
- In the left pane, expand the CA node (click the + icon if collapsed).
- Right-click Certificate Templates and select New > Certificate Template to Issue.
- Locate and select both vSphere 8.x and vSphere 8.x VMCA under the Name column.
- Click OK