Microsoft Windows graphic

To map a certificate to a user account

  1. Open Active Directory Users and Computers.
  2. On the View menu, select Advanced Features.
  3. In the console tree, click Users.

    Or, click the folder that contains the user account.

  4. In the details pane, click the user account to which you want to map a certificate.
  5. On the Action menu, click Name Mappings.
  6. In the Security Identity Mapping dialog box, on the X.509 Certificates tab, click Add.
  7. Type the name and path of the .cer file that contains the certificate you want to map to this user account, and then click Open.
  8. Do one of the following:
    To Do this
    Map the certificate to one account (one-to-one mapping) Confirm that both the Use Issuer for alternate security identity and the Use Subject for alternate security identity check boxes are selected.
    Map any certificate that has the same subject to the user account, regardless of the issuer of the certificate (many-to-one mapping) Clear the Use Issuer for alternate security identity check box, and confirm that the Use Subject for alternate security identity check box is selected.
    Map any certificate that has the same issuer to the user account, regardless of the subject of the certificate (many-to-one mapping) Clear the Use Subject for alternate security identity check box, and confirm that the Use Issuer for alternate security identity check box is selected.

Notes

Related Topics