How does smart card logon certificate enrollment work?

Posted by Purple___Flame@reddit | sysadmin | View on Reddit | 5 comments

Hello, i've been able to create a working smart card logon template and managed to issue a certificate which was promptly written to a usb token, so it does work, but i'm left with few questions..

The current enrollment process - as i have read/enroll permissions, i request certificate from my pc's certificates console and write it to usb(it just automatically prompts it) - is it normal? Certsrv web interface doesn't see my template for whatever reason so i'm unable to use it.

Am i right to assume that "Build from this Active Directory information" in Subject Name tab of template properties means that the user who requests the certificate is also the user for whom the certificate is for, and in that case - how can admin request a certificate for another user?

Lastly - how would(or not) certificate renewal even work potentially, considering we use usb tokens, can they even automatically get new certificates? Or is it simpler to do it manually?